Junglewise Threat Intelligence

CVE-2026-3438: Sonatype Nexus Repository reflected XSS

CVE-2026-3438 · Severity: info · CVSS 5.1 · Published 2026-04-08

Technologies: Sonatype Nexus Repository. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository, a platform used by developers to manage and distribute software components, is affected by a security flaw that could allow an attacker to run malicious scripts in a user's web browser. To exploit this, an attacker would need to trick a logged-in user into clicking a specially crafted link. If successful, this could allow the attacker to perform actions on behalf of the user or steal sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a specially crafted URL to a victim; if the victim clicks the link, arbitrary JavaScript will execute within the context of their browser session. This can lead to session hijacking or unauthorized actions performed on behalf of the user. The issue is resolved in version 3.91.0.

Affected products

  • Sonatype Nexus Repository 3.0.0 through 3.90.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched: Fixed in version 3.91.0

References

Related threats