Back

MEDIUM

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution

Published Aug 27, 2026

Description

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HiddenLayer
Published Aug 27, 2026
Updated Aug 27, 2026
Reserved Aug 25, 2026
CISA Vulnrichment
Updated Aug 27, 2026
NVD
Status Analyzed
Modified Sep 1, 2026
Red Hat
Severity n/a
Public date n/a