Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 03 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Formbricks
Formbricks formbricks |
|
| Vendors & Products |
Formbricks
Formbricks formbricks |
Sat, 03 Oct 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Custom Head Scripts in Formbricks |
Sat, 03 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-03T01:59:10.911Z
Reserved: 2026-10-03T01:59:10.142Z
Link: CVE-2026-105090
No data.
Status : Received
Published: 2026-10-03T02:17:18.370
Modified: 2026-10-03T02:17:18.370
Link: CVE-2026-105090
No data.
OpenCVE Enrichment
Updated: 2026-10-03T05:00:13Z
Weaknesses