CVE-2026-17528: Cross-site Scripting (XSS) in nice-select2
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.
AI Analysis
Technical Summary
CVE-2026-17528 describes a Cross-site Scripting (XSS) vulnerability in the nice-select2 package affecting versions prior to 2.4.1. The issue occurs because user-supplied input via the <select> element is not properly sanitized before being rendered into the DOM, allowing an attacker to inject malicious scripts. This can result in arbitrary script execution in the context of the victim's browser session. The vulnerability has no known exploits in the wild and no official remediation or patch information is currently available.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, defacement, or other client-side attacks. The vulnerability requires user interaction (UI:P) and has a low complexity (AC:L) with no privileges required (PR:N). The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions of nice-select2 or implement input sanitization and output encoding on the <select> element to mitigate XSS risks.
CVE-2026-17528: Cross-site Scripting (XSS) in nice-select2
Description
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.
CVSS v4.0
Score 5.3medium
Affected software
nice-select2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17528 describes a Cross-site Scripting (XSS) vulnerability in the nice-select2 package affecting versions prior to 2.4.1. The issue occurs because user-supplied input via the <select> element is not properly sanitized before being rendered into the DOM, allowing an attacker to inject malicious scripts. This can result in arbitrary script execution in the context of the victim's browser session. The vulnerability has no known exploits in the wild and no official remediation or patch information is currently available.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, defacement, or other client-side attacks. The vulnerability requires user interaction (UI:P) and has a low complexity (AC:L) with no privileges required (PR:N). The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions of nice-select2 or implement input sanitization and output encoding on the <select> element to mitigate XSS risks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- snyk
- Date Reserved
- 2026-07-27T08:44:16.847Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a68d7619c2644c7f8e0517c
Added to database: 07/28/2026, 16:22:57 UTC
Last enriched: 07/29/2026, 23:36:27 UTC
Last updated: 09/11/2026, 22:06:32 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.