Impact
The vulnerability is a reflected XSS flaw that occurs in the Netron desktop application when rendering model files whose node names contain malicious script. The flaw is identified as CWE-79. An attacker can supply a crafted model file that includes unsafe characters, causing the application to execute the embedded script in the context of the user's session. This can conceal nodes, conduct port scanning, or leverage a known Chrome n‑day vulnerability to achieve full remote code execution.
Affected Systems
Netron desktop application, produced by Netron, in all versions up to and including 9.1.2.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate to high risk, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly reported widespread exploitation yet. The likely attack vector requires a user to open a malicious model file, so it is local or social‑engineering based. If an attacker can also exploit a Chrome vulnerability within the Electron runtime used by Netron, remote code execution would be possible.
OpenCVE Enrichment