XSS Vulnerability in Outerbase Studio Affects Various Database Services
CVE-2026-55650
What is CVE-2026-55650?
Outerbase Studio, a browser-based database GUI compatible with PostgreSQL, MySQL, and SQLite, is exposed to a Cross-Site Scripting (XSS) vulnerability due to the unsanitized rendering of Text Widget content. Specifically, in version 0.10.2 and earlier, the application utilizes dangerouslySetInnerHTML in its TextComponent, enabling malicious users to inject executable scripts within the displayed widget. This flaw can lead to local self-XSS attacks. While authentication token theft and account takeover are not concerns in the current architecture, which relies on local browser storage following the discontinuation of Outerbase Cloud in 2025, users should remain vigilant. As of the latest information, no fixed release addressing this vulnerability has been provided.
Affected Version(s)
studio <= 0.10.2
