CVE-2026-1337 describes a cross-site scripting (XSS) vulnerability in Neo4j Enterprise and Community editions prior to version 2026.01, stemming from insufficient escaping of Unicode characters in query logs. An attacker could exploit this by crafting malicious input that, when logged, would execute XSS if an administrator viewed the logs in a tool that interprets them as HTML. Rated as MEDIUM severity with a CVSS score of 5.4, this vulnerability requires user interaction (UI:R) and low privileges (PR:L) for exploitation, with a potential impact of low confidentiality and integrity. There is no evidence of active exploitation, no known Metasploit or ExploitDB modules, and minimal community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.01CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:community:*:*:* | ||
< 2026.01CPE matchmatch criteria | cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.