Impact
Netron, a desktop application for viewing neural network models, contains a reflected XSS vulnerability in versions up to 9.1.2. Unsanitized node names are rendered directly, enabling attackers to inject malicious payloads. This flaw could allow attackers to hide nodes, perform port scanning, or trigger a Chrome n‑day vulnerability that may lead to remote code execution.
Affected Systems
The vulnerability affects the Netron desktop application running version 9.1.2 or older. All builds of these releases that are installed on users’ machines are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate‑to‑high risk. EPSS is not available, so the current exploitation probability is unclear. The CVE is not listed in CISA’s KEV catalog. The attack most likely occurs when an adversary supplies a malicious file containing crafted node names to a local user who opens it with Netron. Because the bug involves reflected XSS, the impact expands only to the context of the user running the application, but if a Chrome n‑day is leveraged, remote code execution could follow.
OpenCVE Enrichment