{"id":"CVE-2026-17528","details":"Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the \u003cselect\u003e element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.","modified":"2026-07-30T03:52:40.278337434Z","published":"2026-07-28T05:00:01.620Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17528.json","cna_assigner":"snyk","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-NICESELECT2-13638683"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17528.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17528"},{"type":"REPORT","url":"https://github.com/bluzky/nice-select2/issues/97"},{"type":"FIX","url":"https://github.com/bluzky/nice-select2/commit/ea23ff404e186f6e2a64a25c530f93165fd2ad26"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bluzky/nice-select2","events":[{"introduced":"0"},{"fixed":"7dc5aca1dff0b6bd976f01378601a5e628eeaba3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.4.1"}],"source":"AFFECTED_FIELD"}}],"versions":["2.4.0","2.3.1","v2.1.0","v2.0.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17528.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N"}]}