CVSS
No CVSS.
A
reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.
References
Configurations
No configuration.
History
14 Jan 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-14 22:15
Updated : 2026-01-16 15:55
NVD link : CVE-2026-0601
Mitre link : CVE-2026-0601
CVE.ORG link : CVE-2026-0601
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')