CVE-2026-78213: Hepta Platforms|Heptabase - Stored Cross-Site Scripting
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hepta Platforms|Heptabaseto a version that resolves this vulnerability.Fixed in 1.93.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated to Heptabase and able to inject persistent malicious content into specific pages. Exploitation can be performed remotely with low attack complexity.
Who is exposed to the malicious code?
Other users are exposed when they click attacker-crafted content on an affected page. The vulnerability can execute arbitrary JavaScript in the context of those users.
Does exploitation require user interaction?
Yes. A victim must click the crafted content for the injected JavaScript to execute.