Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. (CVE-2026-105090)
Formbricks versions before 5.4.4 and 6 before 6.0.1 contain a stored cross-site scripting (XSS) vulnerability. This occurs because the Custom Head Scripts feature at the survey level does not enforce the intended Manage permission boundary, allowing users with readWrite permission to configure scripts. These scripts execute in the authenticated browser session of any user who opens the affected survey, enabling lower-privileged users to run arbitrary JavaScript in higher-privileged users' sessions. The issue is fixed by requiring Manage access to modify survey Custom Head Scripts.
AI Analysis
Technical Summary
The vulnerability in Formbricks before 5.4.4 and 6 before 6.0.1 is a stored XSS caused by improper permission enforcement on the Custom Head Scripts feature. Users with readWrite permission can configure scripts that execute in the browser sessions of other users with higher privileges, violating the documented permission model. This allows arbitrary JavaScript execution within authenticated sessions. The fix enforces that only users with Manage permission can modify these scripts.
Potential Impact
An attacker with readWrite permission can inject arbitrary JavaScript into surveys, which executes in the browser sessions of users with higher privileges. This could lead to session hijacking, unauthorized actions, or data exposure within the context of the affected application. The vulnerability compromises the integrity of user sessions by allowing privilege escalation through script injection.
Mitigation Recommendations
Upgrade Formbricks to version 5.4.4 or later for the 5.x branch, or 6.0.1 or later for the 6.x branch, where the permission enforcement for modifying Custom Head Scripts is corrected to require Manage access. Until upgraded, restrict readWrite permissions carefully to trusted users only.
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. (CVE-2026-105090)
Description
Formbricks versions before 5.4.4 and 6 before 6.0.1 contain a stored cross-site scripting (XSS) vulnerability. This occurs because the Custom Head Scripts feature at the survey level does not enforce the intended Manage permission boundary, allowing users with readWrite permission to configure scripts. These scripts execute in the authenticated browser session of any user who opens the affected survey, enabling lower-privileged users to run arbitrary JavaScript in higher-privileged users' sessions. The issue is fixed by requiring Manage access to modify survey Custom Head Scripts.
CVSS v4.0
Affected software
pkg:github/formbricks/formbricksRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Formbricks before 5.4.4 and 6 before 6.0.1 is a stored XSS caused by improper permission enforcement on the Custom Head Scripts feature. Users with readWrite permission can configure scripts that execute in the browser sessions of other users with higher privileges, violating the documented permission model. This allows arbitrary JavaScript execution within authenticated sessions. The fix enforces that only users with Manage permission can modify these scripts.
Potential Impact
An attacker with readWrite permission can inject arbitrary JavaScript into surveys, which executes in the browser sessions of users with higher privileges. This could lead to session hijacking, unauthorized actions, or data exposure within the context of the affected application. The vulnerability compromises the integrity of user sessions by allowing privilege escalation through script injection.
Mitigation Recommendations
Upgrade Formbricks to version 5.4.4 or later for the 5.x branch, or 6.0.1 or later for the 6.x branch, where the permission enforcement for modifying Custom Head Scripts is corrected to require Manage access. Until upgraded, restrict readWrite permissions carefully to trusted users only.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q9hg-xqvp-x2xv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-105090"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6ac1399ca43b0b3b89d69a70
Added to database: 10/03/2026, 17:21:32 UTC
Last enriched: 10/03/2026, 17:36:12 UTC
Last updated: 10/04/2026, 02:46:02 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.