MEDIUM
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution
Published Aug 27, 2026
6.8
MEDIUMCVSS 4.0
EPSS 0.26%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.