CVE-2026-33061: Jexactyl has Stored DOM Cross-Site Scripting (XSS) via unescaped JSON in Blade template

Published Mar 20, 2026
·
Updated

Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80efab628d1241198ea4f079779cfd inject server-side objects into client-side JavaScript through resources/views/templates/wrapper.blade.php. Using unescaped {!! jsonencode(...) !!} without safe encoding flags allows string values to break out of the JavaScript context and be interpreted as HTML/JS by the browser. If any serialized fields contain attacker-controlled content, such as a username, display name, or site config value, a malicious payload will execute arbitrary script for any user viewing the page (stored DOM XSS). This issue has been patched by commit e28edb204e80efab628d1241198ea4f079779cfd.

Affected Software

11 affected components
Jexactyl>025e8dbb0daaa04054276bda814d922cf4af58da<e28edb204e80efab628d1241198ea4f079779cfd
Jexactyl Jexactyl<=3.8.0
Jexactyl Jexactyl=4.0.0-beta1
Jexactyl Jexactyl=4.0.0-beta2
Jexactyl Jexactyl=4.0.0-beta3
Jexactyl Jexactyl=4.0.0-beta4
Jexactyl Jexactyl=4.0.0-beta5
Jexactyl Jexactyl=4.0.0-beta6
Jexactyl Jexactyl=4.0.0-beta7
Jexactyl Jexactyl=4.0.0-rc1
Jexactyl Jexactyl=4.0.0-rc2

Event History

Mar 20, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33061?

CVE-2026-33061 has a high severity due to its potential for stored DOM Cross-Site Scripting vulnerabilities.

2

How do I fix CVE-2026-33061?

To fix CVE-2026-33061, update your exactyl to a version newer than e28edb204e80efab628d1241198ea4f079779cfd.

3

What causes CVE-2026-33061?

CVE-2026-33061 is caused by unescaped JSON being injected into Blade templates in exactyl.

4

Which software versions are affected by CVE-2026-33061?

CVE-2026-33061 affects exactyl versions between 025e8dbb0daaa04054276bda814d922cf4af58da and e28edb204e80efab628d1241198ea4f079779cfd.

5

Is there a known exploit for CVE-2026-33061?

Yes, CVE-2026-33061 can be exploited by injecting malicious scripts via stored data in exactyl's templating system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203