Description
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.
Published: 2026-10-03
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can execute in the browser session of any survey respondent
Action: Patch
AI Analysis

Impact

Formbricks versions prior to 5.4.4 and 6.0.1 contain a stored cross‑site scripting flaw in the survey‑level Custom Head Scripts feature. The scripts are injected into every page load of a survey and execute with the privileges of the authenticated user. Because the permission check for editing these scripts was not enforced, a member with merely readWrite access may configure malicious scripts. Those scripts run in the browser session of any user who opens the affected survey, allowing the lower‑privileged member to run arbitrary JavaScript in the context of higher‑privileged users, potentially stealing credentials, routing traffic, or modifying page content.

Affected Systems

The vulnerability impacts Formbricks deployments running any version earlier than 5.4.4 or 6.0.1. Administrators who have upgraded to those releases are not affected. The flaw applies to all surveys that have Custom Head Scripts enabled in a workspace where users can modify the scripts without having Manage privileges.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is internal, requiring access to workspace configuration. An attacker that can obtain readWrite permissions can inject malicious code that will run in the browsers of all survey respondents, potentially compromising user sessions or facilitating further attacks. The risk increases in environments where survey respondents include privileged users. Because the flaw is a stored XSS, successful exploitation does not require additional user interaction beyond opening the survey, which lowers the barrier to exploitation.

Generated by OpenCVE AI on October 3, 2026 at 03:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Formbricks to version 5.4.4 or later 6.0.1; these patched releases enforce Manage access for modifying survey Custom Head Scripts
  • Verify that your workspace access controls restrict Custom Head Script edits to users with the Manage role; audit role permissions to ensure the boundary is enforced
  • Review existing Custom Head Scripts in all surveys and remove or sanitize any scripts that may have been injected by lower‑privileged members

Generated by OpenCVE AI on October 3, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Formbricks
Formbricks formbricks
Vendors & Products Formbricks
Formbricks formbricks

Sat, 03 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Custom Head Scripts in Formbricks

Sat, 03 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Description Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Formbricks Formbricks
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-03T01:59:10.911Z

Reserved: 2026-10-03T01:59:10.142Z

Link: CVE-2026-105090

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T02:17:18.370

Modified: 2026-10-03T02:17:18.370

Link: CVE-2026-105090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T05:00:13Z

Weaknesses