{"id":"CVE-2026-105090","title":"Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS","summary":"Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Cu…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","cwe":["CWE-863"],"vendor":"Formbricks","product":"Formbricks","affected":["Formbricks < 5.4.4","Formbricks >= 6.0.0 < 6.0.1"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T02:17:18.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105090","references":[{"url":"https://github.com/formbricks/formbricks/pull/9432","label":"cve@mitre.org"},{"url":"https://github.com/formbricks/formbricks/releases/tag/5.4.4","label":"cve@mitre.org"},{"url":"https://github.com/formbricks/formbricks/releases/tag/6.0.1","label":"cve@mitre.org"},{"url":"https://www.sec4check.pl/blog/posts/cve-formbricks-broken-access-control-stored-xss-custom-head-scripts.html","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-03T02:37:32.155Z","slug":"CVE-2026-105090","body":"## Overview\n\nFormbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}