{"id":"GHSA-wwf9-7jrc-rv4q","summary":"Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure","details":"## Summary\n\nA Stored Cross-Site Scripting (XSS) issue previously existed in the Text Widget in Board of Outerbase Studio where unsanitized HTML could be rendered using `dangerouslySetInnerHTML`\n\n### Steps to Reproduce\n\n1. Create a new dashboard.\n2. Add a **Text widget**.\n3. Insert the following payload:\n\n```html\n\u003cimg src=x onerror=\"alert('XSS Executed\\nToken: ' + localStorage.getItem('ob-token'))\"\u003e\n```\n\n### Architectural Context\n\nOuterbase Cloud and its backend services were discontinued in 2025.\n\nThe current version of Outerbase Studio operates purely as a client-side application, with dashboard data stored locally in the browser.\n\n### Impact\n\nIn the current architecture, the impact is limited to local self-XSS within a user's browser session.\nThe previously described scenarios involving:\n\n- authentication token theft\n- account takeover\n- database access\n\nare no longer applicable since there are no active backend services or authentication tokens.\n\n### Remediation\n\nThe unsafe HTML rendering in the Text Widget has been removed in commit https://github.com/outerbase/studio/commit/b06fb85e5967440278d5a815721b360920566ab9 by eliminating the use of dangerouslySetInnerHTML.","aliases":["CVE-2026-55650"],"modified":"2026-09-10T03:50:50.901075205Z","published":"2026-06-19T21:18:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-19T21:18:44Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/outerbase/studio/security/advisories/GHSA-wwf9-7jrc-rv4q"},{"type":"WEB","url":"https://github.com/outerbase/studio/commit/b06fb85e5967440278d5a815721b360920566ab9"},{"type":"PACKAGE","url":"https://github.com/outerbase/studio"}],"affected":[{"package":{"name":"@outerbase/studio","ecosystem":"npm","purl":"pkg:npm/%40outerbase/studio"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-wwf9-7jrc-rv4q/GHSA-wwf9-7jrc-rv4q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}