Executive brief
Synology Chat Server is a communication platform integrated with Synology's DSM operating system. A cross-site scripting (XSS) vulnerability in the extract domain feature allows authenticated users to inject malicious code via the user interface, potentially enabling them to read or write restricted files and cause limited service disruptions to other users.
Technical details
This is a reflected or stored XSS vulnerability (CWE-79) in the extract domain component of Synology Chat Server before version 2.4.5-22148. The vulnerability requires authentication and user interaction (UI interaction) to exploit. An attacker with valid credentials can craft a malicious input that executes arbitrary JavaScript in the context of a DSM session, allowing file access and limited denial-of-service actions. A patch is available in version 2.4.5-22148 and above.
Affected products
- Synology Chat Server before 2.4.5-22148
Timeline
- 2026-05-26: disclosed: Initial public release of advisory
- 2026-08-28: patched: Vulnerability details disclosed; patch available in 2.4.5-22148 or above