CVE-2026-7308: Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sonatype Nexus Repository 3to a version that resolves this vulnerability.Fixed in 3.92.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7308?
CVE-2026-7308 is considered a high severity vulnerability due to the potential for arbitrary JavaScript execution.
How do I fix CVE-2026-7308?
To fix CVE-2026-7308, upgrade to Nexus Repository version 3.93.0 or later.
Who is affected by CVE-2026-7308?
Authenticated users with upload permissions to hosted repositories in Nexus Repository versions between 3.6.0 and 3.92.0 are affected by CVE-2026-7308.
What type of vulnerability is CVE-2026-7308?
CVE-2026-7308 is a stored Cross-Site Scripting (XSS) vulnerability.
What can attackers achieve with CVE-2026-7308?
Attackers can execute arbitrary JavaScript in the browsers of users who browse the compromised repository directory.