Description
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to execute when the widget is displayed. Outerbase Cloud and its backend services were discontinued in 2025, and the current architecture uses local browser dashboard storage, so the impact is limited to local self-XSS. Authentication token theft, account takeover, and backend database access are not applicable to the current architecture. No fixed release is available as of this review.
Published: 2026-09-15
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Self‑XSS causing token exposure
Action: Assess
AI Analysis

Impact

Outerbase Studio’s TextComponent renders untrusted Text Widget content inside a dangerouslySetInnerHTML, allowing injected markup with script‑capable event handlers to execute when the widget is displayed. Because the vulnerable component is part of a browser‑based user interface, the execution is confined to the local user’s browser session; there is no outbound connection to a cloud service that could breach additional data. A malicious user could therefore read the browser’s local storage where the authentication token is held, leading to session hijack of the local account. Based on the description, the attack vector is local self‑XSS: the attacker must be able to inject arbitrary markup into the Text Widget via the application UI. The lack of server‑side processing or cloud backend in the current architecture limits this to local browser execution. Because the authentication token is only stored locally, and no database or backend access is possible, the impact is limited to a single local user and does not propagate beyond that session.

Affected Systems

Outerbase Studio version 0.10.2 and earlier are affected. The vulnerable component is the TextComponent in src/components/chart/index.tsx. No newer release with a fix is available at this time.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, and the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is a local self‑XSS that requires the attacker to supply content to the Text Widget via the user interface. Once rendered, script‑capable event handlers can read browser local storage, but the limitation to the local browser session restricts the scope of compromise to the account running the instance. No remote code execution, privilege escalation, or database access is possible under the current architecture. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 17, 2026 at 15:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or avoid using the Text Widget feature to prevent the rendering of untrusted markup.
  • If you must use the feature, ensure that any user‑supplied content does not contain script tags or event‑handler attributes; manually scrub the Text Widget content before insertion.
  • Monitor for an official patch or an update from Outerbase; apply the fix at the earliest opportunity once it becomes available.

Generated by OpenCVE AI on September 17, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wwf9-7jrc-rv4q Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Outerbase
Outerbase studio
Vendors & Products Outerbase
Outerbase studio

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to execute when the widget is displayed. Outerbase Cloud and its backend services were discontinued in 2025, and the current architecture uses local browser dashboard storage, so the impact is limited to local self-XSS. Authentication token theft, account takeover, and backend database access are not applicable to the current architecture. No fixed release is available as of this review.
Title Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Outerbase Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:04:16.734Z

Reserved: 2026-06-16T23:52:12.058Z

Link: CVE-2026-55650

cve-icon Vulnrichment

Updated: 2026-09-15T15:03:19.821Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:19.090

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:58:50Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')