CVE-2026-79718: XSS
Published Aug 27, 2026
·Updated
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
Affected Software
1 affected component
Netron<=9.1.2
Event History
Aug 27, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Data Sourced
via NVD·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be considered affected?
Netron desktop application versions 9.1.2 and earlier are affected. Prioritize systems where users open models or other content that may contain attacker-controlled node names.
2
What attacker-controlled data is involved in exploitation?
The issue is triggered through unsanitized node names. An attacker would need to cause malicious node-name content to be processed by the affected desktop application.
3
How can I determine whether a system is exposed?
Check the installed Netron desktop application version. Versions at or below 9.1.2 should be treated as affected.