medium · CVSS v3 5.4 · CVSS v4 5.1
CVE-2026-105090
Formbricks versions prior to 5.4.4 and 6.0.1 allow stored XSS via the Custom Head Scripts feature, which incorrectly permits readWrite users
Overview
Formbricks versions prior to 5.4.4 and 6.0.1 allow stored XSS via the Custom Head Scripts feature, which incorrectly permits readWrite users to inject scripts. The vulnerability lets a lower‑privileged member run arbitrary JavaScript in the browser session of any survey viewer, including higher‑privileged users. This can lead to data theft or session hijacking within the application.
Description
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.
Impact
The stored XSS flaw compromises confidentiality and integrity by allowing attackers to execute arbitrary code in authenticated user sessions. It can also lead to session hijacking or unauthorized data exfiltration. Higher‑privileged users, such as administrators or survey owners, are at risk when they view affected surveys.
Remediation
Upgrade to Formbricks 5.4.4 or later, or 6.0.1 or later, to enforce the Manage permission boundary on Custom Head Scripts. If an upgrade is not immediately possible, disable the Custom Head Scripts feature or restrict it to users with Manage role. Monitor for unexpected script activity and review survey configurations for unauthorized scripts.
Risk context
The CVSS v3 score of 5.4 indicates medium risk, and no EPSS data is available. Defenders should treat this as a moderate‑urgency issue, applying patches promptly to prevent potential data compromise.
Affected products
- Formbricks 5.x
- Formbricks 6.x
Scores
- Severity
- medium
- CVSS v2
- 3.5
- CVSS v3
- 5.4
- CVSS v4
- 5.1
- EPSS
- —