---
id: CVE-2026-3438
title: >-
  A reflected cross-site scripting vulnerability exists in Sonatype Nexus
  Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote
  attackers to execute arbitrary JavaScript in a victim's browser through a
  specially craft…
summary: >-
  A reflected cross-site scripting vulnerability exists in Sonatype Nexus
  Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote
  attackers to execute arbitrary JavaScript in a victim's browser through a
  specially craft…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: sonatype
product: nexus_repository_manager
affected:
  - 'nexus_repository_manager >= 3.0.0, < 3.91.0'
patched:
  - nexus_repository_manager 3.91.0
published: '2026-04-08'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:38:49.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3438'
references:
  - url: >-
      https://help.sonatype.com/en/sonatype-nexus-repository-3-91-0-release-notes.html
    label: 103e4ec9-0a87-450b-af77-479448ddef11
  - url: 'https://support.sonatype.com/hc/en-us/articles/50609137161363'
    label: 103e4ec9-0a87-450b-af77-479448ddef11
tags:
  - nvd
epss: 0.00611
epssPercentile: 0.47001
ingestedAt: '2026-09-18T15:44:31.549Z'
---

## Overview

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

## Affected

- `nexus_repository_manager >= 3.0.0, < 3.91.0`

## Remediation

Upgrade past the affected range:

- `nexus_repository_manager 3.91.0`
