Junglewise Threat Intelligence

CVE-2026-9548: Synology Chat Server XSS in extract domain

CVE-2026-9548 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Technologies: Synology Chat Server. Vendors: Synology.

Executive brief

Synology Chat Server is a communication platform integrated with Synology's DSM operating system. A cross-site scripting (XSS) vulnerability in the extract domain feature allows authenticated users to inject malicious code via the user interface, potentially enabling them to read or write restricted files and cause limited service disruptions to other users.

Technical details

This is a reflected or stored XSS vulnerability (CWE-79) in the extract domain component of Synology Chat Server before version 2.4.5-22148. The vulnerability requires authentication and user interaction (UI interaction) to exploit. An attacker with valid credentials can craft a malicious input that executes arbitrary JavaScript in the context of a DSM session, allowing file access and limited denial-of-service actions. A patch is available in version 2.4.5-22148 and above.

Affected products

  • Synology Chat Server before 2.4.5-22148

Timeline

  • 2026-05-26: disclosed: Initial public release of advisory
  • 2026-08-28: patched: Vulnerability details disclosed; patch available in 2.4.5-22148 or above

References

Related threats