PT-2026-45788 · Appsmith · Appsmith

·

CVE-2026-7299

·

Published

2026-06-02

·

Updated

2026-06-30

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 2.1
Description The SQL query editor's autocomplete functionality fails to sanitize database object names before rendering them using innerHTML. This allows an authenticated Developer with access to a shared PostgreSQL datasource to inject persistent Cross-Site Scripting (XSS) by creating malicious table or column names. When other workspace members interact with the same datasource and trigger the autocomplete feature, the unsanitized names execute arbitrary JavaScript in their sessions, potentially leading to session hijacking, privilege escalation, or credential theft.
Recommendations Update to version 2.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-49979
BIT-APPSMITH-2026-7299
CVE-2026-7299
GHSA-VVXF-F8Q9-86GH

Affected Products

Appsmith