Executive brief
Synology Chat Server is a messaging platform deployed in Synology's DSM data center operating system. A cross-site scripting (XSS) vulnerability in the domain extraction component allows authenticated users to inject malicious scripts that execute in other users' browsers, enabling unauthorized file access, data modification, or service disruption across the DSM environment.
Technical details
CVE-2026-40541 is an improper input neutralization vulnerability (CWE-79) in the domain extraction functionality of Synology Chat Server versions before 2.4.5-22148. The vulnerability requires authentication and user interaction (clicking malicious links or content). An authenticated attacker can inject arbitrary JavaScript that executes with the privileges of the victim's session in a DSM context, allowing them to read/write arbitrary files and conduct denial-of-service attacks. The fix is available in Synology Chat Server 2.4.5-22148 and later.
Affected products
- Synology Chat Server before 2.4.5-22148
Timeline
- 2026-05-26: disclosed
- 2026-05-26: patched: Fix available in version 2.4.5-22148 or later