Executive brief
Heptabase is a collaborative note-taking and knowledge management platform. An authenticated user can inject malicious JavaScript code that persists on specific pages, causing arbitrary code to execute in the browsers of other users who view the infected content. This can lead to account compromise, data theft, or unauthorized actions performed on behalf of other users.
Technical details
The vulnerability is a stored (persistent) cross-site scripting (XSS) flaw in Heptabase that allows authenticated attackers to inject malicious JavaScript into specific pages. The vulnerable component handles user-supplied content without proper input validation or output encoding. The attack requires authentication and user interaction—a victim must click or view the crafted content for the malicious script to execute in their browser. Successful exploitation enables arbitrary JavaScript execution in the victim's session, potentially leading to session hijacking, credential theft, or malicious actions. The vulnerability is resolved in version 1.93.1 and later.
Affected products
- Hepta Platforms Heptabase before 1.93.1 (affecting 1.91.3 and earlier)
Timeline
- 2026-08-24: disclosed
- other: Patch available in version 1.93.1 or later