Reflected Cross-Site Scripting Vulnerability in Sonatype Nexus Repository
CVE-2026-3438
5.1MEDIUM
What is CVE-2026-3438?
A reflected cross-site scripting vulnerability in Sonatype Nexus Repository allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by utilizing a specially crafted URL. This exploitation requires the victim to interact with the malicious link, potentially leading to unauthorized actions and data disclosure.
Affected Version(s)
Nexus Repository 3.0.0 < 3.91.0
