Description
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
Published: 2026-08-28
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Access and Denial of Service
Action: Immediate Patch
AI Analysis

Impact

An improper neutralization of input during web page generation, specifically in the extract domain functionality, is present in Synology Chat Server versions before 2.4.5-22148. The vulnerability allows a remote authenticated user to interact with the UI to read or write arbitrary files and to conduct denial‑of-service attacks against the DiskStation Manager (DSM). This can result in unauthorized file manipulation or service disruption.

Affected Systems

The affected product is Synology Chat Server. Versions earlier than 2.4.5-22148 are vulnerable. The issue exists within the DSM web interface used to manage the chat service.

Risk and Exploitability

The CVSS score of 9.0 classifies this as a critical vulnerability, and while the EPSS score is not available, the lack of a KEV listing does not diminish the seriousness of the flaw. The likely attack vector is an authenticated attacker who can access the chat server’s UI on the DSM host. Such an attacker can upload or overwrite files, potentially modifying or deleting critical data, or crash the application through crafted input. The high severity and potential for arbitrary file access and denial‑of-service make immediate remediation essential.

Generated by OpenCVE AI on August 28, 2026 at 11:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Synology Chat Server to version 2.4.5-22148 or later.
  • Apply all current DSM security patches to address the underlying web interface vulnerability.
  • Restrict access to the Chat Server UI to trusted, least‑privileged users only and monitor for anomalous file changes or denial‑of‑service symptoms.

Generated by OpenCVE AI on August 28, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology synology Chat Server
Vendors & Products Synology
Synology synology Chat Server

Fri, 28 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Synology Chat Server Allowing Remote Authenticated Arbitrary File Access and DoS

Fri, 28 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Synology Chat Server Allowing Remote Authenticated Arbitrary File Access and DoS

Fri, 28 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Synology Synology Chat Server
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-08-28T11:44:42.311Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40541

cve-icon Vulnrichment

Updated: 2026-08-28T11:44:38.594Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-28T08:16:40.713

Modified: 2026-09-01T20:54:51.287

Link: CVE-2026-40541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:22:01Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')