{"id":"BIT-neo4j-2026-1337","summary":"Insufficient escaping of unicode characters in query log","details":"Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.\n\nProof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337","aliases":["BIT-neo4j-enterprise-2026-1337","CVE-2026-1337","GHSA-xr72-g735-4vwp"],"modified":"2026-09-10T16:01:43.970195073Z","published":"2026-02-26T15:16:17.899Z","database_specific":{"cpes":["cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:neo4j:neo4j:*:*:*:*:community:*:*:*"],"severity":"Medium"},"references":[{"type":"ADVISORY","url":"https://github.com/JoakimBulow/CVE-2026-1337"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1337"}],"affected":[{"package":{"name":"neo4j","ecosystem":"Bitnami","purl":"pkg:bitnami/neo4j"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.1.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/neo4j/BIT-neo4j-2026-1337.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}],"schema_version":"1.9.0"}