XSS Vulnerability in Outerbase Studio Affects Various Database Services
CVE-2026-55650

4.4MEDIUM

Key Information:

Vendor

Outerbase

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-55650?

Outerbase Studio, a browser-based database GUI compatible with PostgreSQL, MySQL, and SQLite, is exposed to a Cross-Site Scripting (XSS) vulnerability due to the unsanitized rendering of Text Widget content. Specifically, in version 0.10.2 and earlier, the application utilizes dangerouslySetInnerHTML in its TextComponent, enabling malicious users to inject executable scripts within the displayed widget. This flaw can lead to local self-XSS attacks. While authentication token theft and account takeover are not concerns in the current architecture, which relies on local browser storage following the discontinuation of Outerbase Cloud in 2025, users should remain vigilant. As of the latest information, no fixed release addressing this vulnerability has been provided.

Affected Version(s)

studio <= 0.10.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.