---
id: CVE-2026-105090
title: Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS
summary: >-
  Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level
  Custom Head Scripts feature did not enforce the documented Manage permission
  boundary. A workspace member holding only readWrite permission could configure
  Cu…
severity: medium
cvss: 5.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'
cwe:
  - CWE-863
vendor: Formbricks
product: Formbricks
affected:
  - Formbricks < 5.4.4
  - Formbricks >= 6.0.0 < 6.0.1
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T02:17:18.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105090'
references:
  - url: 'https://github.com/formbricks/formbricks/pull/9432'
    label: cve@mitre.org
  - url: 'https://github.com/formbricks/formbricks/releases/tag/5.4.4'
    label: cve@mitre.org
  - url: 'https://github.com/formbricks/formbricks/releases/tag/6.0.1'
    label: cve@mitre.org
  - url: >-
      https://www.sec4check.pl/blog/posts/cve-formbricks-broken-access-control-stored-xss-custom-head-scripts.html
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-03T02:37:32.155Z'
---

## Overview

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
