Impact
Outerbase Studio’s TextComponent renders untrusted Text Widget content inside a dangerouslySetInnerHTML, allowing injected markup with script‑capable event handlers to execute when the widget is displayed. Because the vulnerable component is part of a browser‑based user interface, the execution is confined to the local user’s browser session; there is no outbound connection to a cloud service that could breach additional data. A malicious user could therefore read the browser’s local storage where the authentication token is held, leading to session hijack of the local account. Based on the description, the attack vector is local self‑XSS: the attacker must be able to inject arbitrary markup into the Text Widget via the application UI. The lack of server‑side processing or cloud backend in the current architecture limits this to local browser execution. Because the authentication token is only stored locally, and no database or backend access is possible, the impact is limited to a single local user and does not propagate beyond that session.
Affected Systems
Outerbase Studio version 0.10.2 and earlier are affected. The vulnerable component is the TextComponent in src/components/chart/index.tsx. No newer release with a fix is available at this time.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is a local self‑XSS that requires the attacker to supply content to the Text Widget via the user interface. Once rendered, script‑capable event handlers can read browser local storage, but the limitation to the local browser session restricts the scope of compromise to the account running the instance. No remote code execution, privilege escalation, or database access is possible under the current architecture. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Github GHSA