Impact
Formbricks versions prior to 5.4.4 and 6.0.1 contain a stored cross‑site scripting flaw in the survey‑level Custom Head Scripts feature. The scripts are injected into every page load of a survey and execute with the privileges of the authenticated user. Because the permission check for editing these scripts was not enforced, a member with merely readWrite access may configure malicious scripts. Those scripts run in the browser session of any user who opens the affected survey, allowing the lower‑privileged member to run arbitrary JavaScript in the context of higher‑privileged users, potentially stealing credentials, routing traffic, or modifying page content.
Affected Systems
The vulnerability impacts Formbricks deployments running any version earlier than 5.4.4 or 6.0.1. Administrators who have upgraded to those releases are not affected. The flaw applies to all surveys that have Custom Head Scripts enabled in a workspace where users can modify the scripts without having Manage privileges.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is internal, requiring access to workspace configuration. An attacker that can obtain readWrite permissions can inject malicious code that will run in the browsers of all survey respondents, potentially compromising user sessions or facilitating further attacks. The risk increases in environments where survey respondents include privileged users. Because the flaw is a stored XSS, successful exploitation does not require additional user interaction beyond opening the survey, which lowers the barrier to exploitation.
OpenCVE Enrichment