CVE-2026-9548: XSS
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology Chat Serverto a version that resolves this vulnerability.Fixed in 2.4.5-22148
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote authenticated user can exploit it, but successful exploitation also requires a UI interaction. The issue affects Synology Chat Server before version 2.4.5-22148.
What could an attacker do if exploitation succeeds?
The vulnerability may allow an attacker to read or write restricted files and perform limited denial-of-service attacks in DSM. The impact on confidentiality, integrity, and availability is rated low.
What should be done to remediate it?
Update Synology Chat Server to version 2.4.5-22148 or later. The provided data does not describe a workaround for systems that cannot be patched immediately.