{"id":"CVE-2026-79720","aliases":["PYSEC-2026-3747"],"title":"Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, …","summary":"Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.","severity":"medium","cvss":5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"netron","product":"netron","ecosystem":"pip","affected":["netron < 9.1.3"],"patched":["netron 9.1.3"],"published":"2026-08-27","updated":"2026-09-02","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2026-3747","references":[{"url":"https://github.com/lutzroeder/netron/commit/cd14bad8c9132b1aaf1d197fe61925575f194f00"},{"url":"https://www.hiddenlayer.com/sai-security-advisory/2026-08-netron"}],"tags":["osv","pip"],"epss":0.00184,"epssPercentile":0.08206,"ingestedAt":"2026-09-02T19:31:24.955Z","slug":"CVE-2026-79720","body":"## Overview\n\nReflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.\n\n## Affected packages\n\n- `netron < 9.1.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `netron 9.1.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}