CVE-2026-30862

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be interpolated into the DOM. By leveraging the "Invite Users" feature, an attacker with a regular user account (user@gmail.com) can force a System Administrator to execute a high-privileged API call (/api/v1/admin/env), resulting in a Full Administrative Account Takeover. This vulnerability is fixed in 1.96.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*

History

13 Mar 2026, 15:34

Type Values Removed Values Added
Summary
  • (es) Appsmith es una plataforma para construir paneles de administración, herramientas internas y cuadros de mando. Anterior a la 1.96, existe una vulnerabilidad XSS Almacenado Crítica en el Widget de Tabla (TableWidgetV2). La causa raíz es una falta de saneamiento de HTML en el pipeline de renderizado de componentes de React, permitiendo que atributos maliciosos sean interpolados en el DOM. Aprovechando la característica 'Invitar Usuarios', un atacante con una cuenta de usuario regular (user@gmail.com) puede forzar a un Administrador del Sistema a ejecutar una llamada a la API con altos privilegios (/api/v1/admin/env), resultando en una Toma de Control Completa de la Cuenta Administrativa. Esta vulnerabilidad está corregida en la 1.96.
CPE cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
References () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-5hw4-whxv-6794 - () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-5hw4-whxv-6794 - Exploit, Mitigation, Vendor Advisory
First Time Appsmith
Appsmith appsmith

10 Mar 2026, 18:18

Type Values Removed Values Added
References () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-5hw4-whxv-6794 - () https://github.com/appsmithorg/appsmith/security/advisories/GHSA-5hw4-whxv-6794 -

10 Mar 2026, 17:40

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 17:40

Updated : 2026-03-13 15:34


NVD link : CVE-2026-30862

Mitre link : CVE-2026-30862

CVE.ORG link : CVE-2026-30862


JSON object : View

Products Affected

appsmith

  • appsmith
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')