Executive brief
Pega Platform, a low-code application development tool, is affected by a security flaw in its user interface component. An attacker with developer-level access could inject malicious scripts that execute when other users interact with the system. This could lead to unauthorized actions or the theft of sensitive session information within the development environment.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Dev Studio component of Pega Platform versions 8.1.0 through 25.1.2. The flaw allows a high-privileged user with a developer role to inject malicious scripts into the user interface. These scripts are then executed in the browser of other users who view the affected component. Exploitation requires network access and user interaction from the victim. Pegasystems has released patches (24.2.4, 25.1.3) and specific hotfixes (HFIX-D578, HFIX-D579, HFIX-D580) to remediate the issue.
Affected products
- Pegasystems Pega Platform 8.1.0 through 25.1.2
Timeline
- 2026-07-15: advisory: Initial advisory published by Pegasystems and NVD record created.