Executive brief
Synology DiskStation Manager (DSM) is a network storage system operating system used by businesses to manage and access files across their infrastructure. A cross-site scripting flaw in the Video API allows authenticated users to inject malicious code that executes when the video player is used, potentially enabling them to read or write limited files on the system. This could lead to unauthorized data access or modification within the storage environment.
Technical details
The vulnerability is an improper neutralization of input during web page generation (CWE-79: Cross-site Scripting) in the Video API component. An authenticated attacker can craft malicious input that is not properly sanitized before being rendered in the video player interface, allowing arbitrary JavaScript execution. The vulnerability requires authentication and user interaction (launching the player), and operates within a single context (no cookie stealing across sites). Exploitation enables reading or writing limited files on the affected system. Patches are available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Patches released: DSM 7.2.1-69057-10, 7.2.2-72806-7, 7.3.2-86009-2