Executive brief
Pega Platform, a low-code application development suite, is affected by a security flaw in its Dev Studio user interface. An attacker could potentially execute malicious scripts in the browser of a high-privileged developer or administrator. While this could lead to unauthorized actions within the platform, the risk is mitigated by the requirement that the attacker must already possess high-level developer credentials or trick such a user into clicking a malicious link.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Dev Studio component of Pegasystems Pega Platform versions 8.1.0 through 25.1.2. The flaw allows for the injection of malicious scripts into the user interface, which are then executed in the context of the victim's browser session. Exploitation requires a high-privileged user with a developer role and typically involves user interaction, such as clicking a specially crafted link. Successful exploitation could allow an attacker to perform actions on behalf of the developer or access sensitive session information. Pegasystems has released patches (24.2.4, 25.1.3) and specific hotfixes for versions 23.1.5, 24.1.4, and 25.1.2 to remediate this issue.
Affected products
- Pegasystems Pega Platform 8.1.0 through 25.1.2
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory
- 2026-07-15: patched