
CVE-2026-7308 An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses… https://www.cve.org/CVERecord?id=CVE-2026-7308
Post summary
The CVE involves an authenticated upload‑based XSS that allows arbitrary JavaScript execution in users’ browsers, but no exploit code, patch, or active exploitation details are provided.
