Junglewise Threat Intelligence

CVE-2026-48167: Filament stored XSS in ImageColumn and ImageEntry components

CVE-2026-48167 · Severity: medium · CVSS 6.4 · Published 2026-06-22

Vendors: Filament.

Executive brief

Filament is a popular framework for building administration panels and dashboards in PHP. A vulnerability in its image display components allows attackers to inject malicious scripts into the database. When other users, such as administrators, view these images in a table or list, the scripts could execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

The vulnerability is a stored Cross-Site Scripting (XSS) flaw (CWE-79) within the ImageColumn and ImageEntry components of the Filament ecosystem. These components fail to properly escape HTML when rendering raw values retrieved from the database. An attacker with the ability to write data to fields rendered by these components can inject malicious HTML or JavaScript. The exploit occurs when a user views a table or schema containing the malicious entry; because the 'Scope' is changed (S:C) in the CVSS metric, the script can execute in the context of the administrative interface. The issue is fixed in versions 4.11.5 and 5.6.5.

Affected products

  • Filament filament/infolists >= 4.0.0, <= 4.11.4; >= 5.0.0, <= 5.6.4
  • Filament filament/tables >= 4.0.0, <= 4.11.4; >= 5.0.0, <= 5.6.4

Timeline

  • 2026-05-23: disclosed
  • 2026-06-22: advisory: NVD publication date
  • 2026-06-23: patched: GitHub Advisory published and reviewed

References