Junglewise Threat Intelligence

CVE-2026-40541: Synology Chat Server cross-site scripting in domain extraction

CVE-2026-40541 · Severity: critical · CVSS 9 · Published 2026-08-28

Technologies: Synology Chat Server. Vendors: Synology.

Executive brief

Synology Chat Server is a messaging platform deployed in Synology's DSM data center operating system. A cross-site scripting (XSS) vulnerability in the domain extraction component allows authenticated users to inject malicious scripts that execute in other users' browsers, enabling unauthorized file access, data modification, or service disruption across the DSM environment.

Technical details

CVE-2026-40541 is an improper input neutralization vulnerability (CWE-79) in the domain extraction functionality of Synology Chat Server versions before 2.4.5-22148. The vulnerability requires authentication and user interaction (clicking malicious links or content). An authenticated attacker can inject arbitrary JavaScript that executes with the privileges of the victim's session in a DSM context, allowing them to read/write arbitrary files and conduct denial-of-service attacks. The fix is available in Synology Chat Server 2.4.5-22148 and later.

Affected products

  • Synology Chat Server before 2.4.5-22148

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: patched: Fix available in version 2.4.5-22148 or later

References

Related threats