Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netron
Netron netron |
|
| Vendors & Products |
Netron
Netron netron |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS in Netron Enabling Remote Code Execution via Unsanitized Node Names |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: HiddenLayer
Published: 2026-08-27T16:40:09.913Z
Updated: 2026-08-27T18:49:38.838Z
Reserved: 2026-08-25T13:43:20.741Z
Link: CVE-2026-79720
No data.
Status : Awaiting Analysis
Published: 2026-08-27T17:20:49.027
Modified: 2026-08-31T19:36:42.500
Link: CVE-2026-79720
No data.