Junglewise Threat Intelligence

CVE-2026-17528: bluzky nice-select2 Cross-site Scripting in select element rendering

CVE-2026-17528 · Severity: medium · CVSS 6.1 · Published 2026-07-28

Executive brief

nice-select2 is a JavaScript library used to create customizable dropdown menus on websites. A security flaw allows attackers to inject malicious scripts into these dropdowns if the website displays untrusted data within a selection menu. If a user interacts with the affected menu, the attacker's script could run in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A Cross-site Scripting (XSS) vulnerability exists in nice-select2 versions prior to 2.4.1. The issue stems from the library's failure to properly sanitize or escape content passed into the native <select> element before rendering it into the custom DOM structure (specifically within the .current span and .list items). An attacker can provide a malicious payload, such as a script tag within an option label, which is then executed in the context of the victim's browser session when the page is viewed or interacted with. This is a DOM-based XSS vulnerability triggered by unsafe DOM manipulation. The vulnerability is resolved in version 2.4.1 by implementing proper output encoding.

Affected products

  • bluzky nice-select2 < 2.4.1

Timeline

  • 2025-07-30: disclosed: Vulnerability reported via GitHub issue #97
  • 2026-07-27: advisory: Snyk advisory published
  • 2026-07-28: advisory: NVD entry published

References