CVE-2026-55650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in outerbase studio
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to execute when the widget is displayed. Outerbase Cloud and its backend services were discontinued in 2025, and the current architecture uses local browser dashboard storage, so the impact is limited to local self-XSS. Authentication token theft, account takeover, and backend database access are not applicable to the current architecture. No fixed release is available as of this review.
AI Analysis
Technical Summary
Outerbase Studio, a browser-based database GUI supporting PostgreSQL, MySQL, and SQLite, has a CWE-79 cross-site scripting vulnerability in versions 0.10.2 and earlier. The issue is in the TextComponent (src/components/chart/index.tsx), which uses dangerouslySetInnerHTML to render Text Widget content without sanitization. This allows an attacker to inject markup with script-capable event handlers that execute when the widget is displayed. The discontinued Outerbase Cloud and backend services mean the vulnerability's impact is limited to local self-XSS scenarios, with no risk of authentication token theft, account takeover, or backend database access. No patch or fixed release is currently available.
Potential Impact
The vulnerability enables execution of injected scripts in the context of the local browser dashboard storage, leading to local self-XSS. Due to the discontinued cloud services and backend, there is no risk of remote exploitation affecting authentication tokens, account takeover, or backend database compromise. The CVSS 3.1 base score is 4.4 (medium severity), reflecting limited impact confined to local user interaction.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Since the impact is limited to local self-XSS due to the discontinued cloud backend and local storage architecture, no urgent remediation is mandated. Users should exercise caution when entering or rendering untrusted content in Text Widgets. Monitor the vendor advisory for any future updates or patches.
CVE-2026-55650: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in outerbase studio
Description
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to execute when the widget is displayed. Outerbase Cloud and its backend services were discontinued in 2025, and the current architecture uses local browser dashboard storage, so the impact is limited to local self-XSS. Authentication token theft, account takeover, and backend database access are not applicable to the current architecture. No fixed release is available as of this review.
CVSS v3.1
Score 4.4medium
Affected software
outerbase
studio
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Outerbase Studio, a browser-based database GUI supporting PostgreSQL, MySQL, and SQLite, has a CWE-79 cross-site scripting vulnerability in versions 0.10.2 and earlier. The issue is in the TextComponent (src/components/chart/index.tsx), which uses dangerouslySetInnerHTML to render Text Widget content without sanitization. This allows an attacker to inject markup with script-capable event handlers that execute when the widget is displayed. The discontinued Outerbase Cloud and backend services mean the vulnerability's impact is limited to local self-XSS scenarios, with no risk of authentication token theft, account takeover, or backend database access. No patch or fixed release is currently available.
Potential Impact
The vulnerability enables execution of injected scripts in the context of the local browser dashboard storage, leading to local self-XSS. Due to the discontinued cloud services and backend, there is no risk of remote exploitation affecting authentication tokens, account takeover, or backend database compromise. The CVSS 3.1 base score is 4.4 (medium severity), reflecting limited impact confined to local user interaction.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Since the impact is limited to local self-XSS due to the discontinued cloud backend and local storage architecture, no urgent remediation is mandated. Users should exercise caution when entering or rendering untrusted content in Text Widgets. Monitor the vendor advisory for any future updates or patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:52:12.058Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa95a7655bf5e2cf5f52f65
Added to database: 09/15/2026, 14:47:18 UTC
Last enriched: 09/15/2026, 15:01:47 UTC
Last updated: 09/16/2026, 02:10:59 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.