CVE-2026-33061Disclosure(jexactyl / jexactyl)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80efab628d1241198ea4f079779cfd inject server-side objects into client-side JavaScript through resources/views/templates/wrapper.blade.php. Using unescaped {!! json_encode(...) !!} without safe encoding flags allows string values to break out of the JavaScript context and be interpreted as HTML/JS by the browser. If any serialized fields contain attacker-controlled content, such as a username, display name, or site config value, a malicious payload will execute arbitrary script for any user viewing the page (stored DOM XSS). This issue has been patched by commit e28edb204e80efab628d1241198ea4f079779cfd.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jexactyl

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
jexactyl

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-20: 1Technical Details · 2026-03-20: 103-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33061 - exactyl has Stored DOM Cross-Site Scripting (XSS) via unescaped JSON in Blade template Intel Report: https://ift.tt/3kVi5Ty

    Post summary

    The text announces the CVE-2026-33061 vulnerability, detailing it as a Stored DOM XSS via unescaped JSON in a Blade template, with no evidence of PoC, exploit, or patch information.

    0000034
    334 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appjexactyljexactyl---
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--
Appjexactyljexactyl4.0.0--

Explore more