CVE-2026-79720: XSS
Published Aug 27, 2026
·Updated
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
Affected Software
1 affected component
Netron<=9.1.2
Event History
Aug 27, 2026
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionWeakness
Data Sourced
via NVD·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects the Netron desktop application in versions 9.1.2 and earlier. The provided information does not indicate that other deployment types are affected.
2
What must an attacker control to exploit this issue?
An attacker needs to supply or cause the application to process a node name containing unsanitized content. That content can trigger reflected XSS in the desktop application.
3
What could exploitation enable?
An attacker may hide certain nodes or perform port scanning. The advisory also states that abuse of a Chrome n-day could lead to remote code execution.