rootpwn

medium · CVSS v3 5.4 · CVSS v4 5.1

CVE-2026-105090

Formbricks versions prior to 5.4.4 and 6.0.1 allow stored XSS via the Custom Head Scripts feature, which incorrectly permits readWrite users

Overview

Formbricks versions prior to 5.4.4 and 6.0.1 allow stored XSS via the Custom Head Scripts feature, which incorrectly permits readWrite users to inject scripts. The vulnerability lets a lower‑privileged member run arbitrary JavaScript in the browser session of any survey viewer, including higher‑privileged users. This can lead to data theft or session hijacking within the application.

Description

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.

Impact

The stored XSS flaw compromises confidentiality and integrity by allowing attackers to execute arbitrary code in authenticated user sessions. It can also lead to session hijacking or unauthorized data exfiltration. Higher‑privileged users, such as administrators or survey owners, are at risk when they view affected surveys.

Remediation

Upgrade to Formbricks 5.4.4 or later, or 6.0.1 or later, to enforce the Manage permission boundary on Custom Head Scripts. If an upgrade is not immediately possible, disable the Custom Head Scripts feature or restrict it to users with Manage role. Monitor for unexpected script activity and review survey configurations for unauthorized scripts.

Risk context

The CVSS v3 score of 5.4 indicates medium risk, and no EPSS data is available. Defenders should treat this as a moderate‑urgency issue, applying patches promptly to prevent potential data compromise.

Affected products

  • Formbricks 5.x
  • Formbricks 6.x

Scores

Severity
medium
CVSS v2
3.5
CVSS v3
5.4
CVSS v4
5.1
EPSS
—

stored-xss permission-bypass Formbricks survey web-application

← All CVEs