Skip to main content
EPSS 0.3%top 84%

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. (CVE-2026-105090)

0
Medium
Published: 10/03/2026 (10/03/2026, 03:31:32 UTC)
Source: GCVE Database

Description

Formbricks versions before 5.4.4 and 6 before 6.0.1 contain a stored cross-site scripting (XSS) vulnerability. This occurs because the Custom Head Scripts feature at the survey level does not enforce the intended Manage permission boundary, allowing users with readWrite permission to configure scripts. These scripts execute in the authenticated browser session of any user who opens the affected survey, enabling lower-privileged users to run arbitrary JavaScript in higher-privileged users' sessions. The issue is fixed by requiring Manage access to modify survey Custom Head Scripts.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
Passive
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
Low
Subsq. Integrity
Low
Subsq. Availability
None
Scope
X
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected software

GitHub Actionsmore threats →ai
formbricks/formbricks
pkg:github/formbricks/formbricks
Affected versions
<5.4.4<6.0.1 >=6.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:36:12 UTC

Technical Analysis

The vulnerability in Formbricks before 5.4.4 and 6 before 6.0.1 is a stored XSS caused by improper permission enforcement on the Custom Head Scripts feature. Users with readWrite permission can configure scripts that execute in the browser sessions of other users with higher privileges, violating the documented permission model. This allows arbitrary JavaScript execution within authenticated sessions. The fix enforces that only users with Manage permission can modify these scripts.

Potential Impact

An attacker with readWrite permission can inject arbitrary JavaScript into surveys, which executes in the browser sessions of users with higher privileges. This could lead to session hijacking, unauthorized actions, or data exposure within the context of the affected application. The vulnerability compromises the integrity of user sessions by allowing privilege escalation through script injection.

Mitigation Recommendations

Upgrade Formbricks to version 5.4.4 or later for the 5.x branch, or 6.0.1 or later for the 6.x branch, where the permission enforcement for modifying Custom Head Scripts is corrected to require Manage access. Until upgraded, restrict readWrite permissions carefully to trusted users only.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-q9hg-xqvp-x2xv
Osv Schema Version
1.4.0
Aliases
["CVE-2026-105090"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6ac1399ca43b0b3b89d69a70

Added to database: 10/03/2026, 17:21:32 UTC

Last enriched: 10/03/2026, 17:36:12 UTC

Last updated: 10/04/2026, 02:46:02 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses