{"id":"GHSA-xr72-g735-4vwp","summary":"Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log","details":"Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.\n\nProof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337","aliases":["BIT-neo4j-2026-1337","BIT-neo4j-enterprise-2026-1337","CVE-2026-1337"],"modified":"2026-09-10T03:50:36.168487833Z","published":"2026-02-06T15:31:03Z","database_specific":{"github_reviewed_at":"2026-02-06T19:41:15Z","nvd_published_at":"2026-02-06T14:16:38Z","cwe_ids":["CWE-117"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1337"},{"type":"WEB","url":"https://github.com/JoakimBulow/CVE-2026-1337"},{"type":"PACKAGE","url":"https://github.com/neo4j/neo4j"}],"affected":[{"package":{"name":"org.neo4j:neo4j","ecosystem":"Maven","purl":"pkg:maven/org.neo4j/neo4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.01"}]}],"versions":["1.2","1.2.M01","1.2.M02","1.2.M03","1.2.M04","1.2.M05","1.2.M06","1.3","1.3.M01","1.3.M02","1.3.M03","1.3.M04","1.3.M05","1.4","1.4.1","1.4.2","1.4.M01","1.4.M02","1.4.M03","1.4.M04","1.4.M05","1.4.M06","1.5","1.5.1","1.5.2","1.5.3","1.5.M01","1.5.M02","1.6","1.6.1","1.6.2","1.6.3","1.6.M01","1.6.M02","1.6.M03","1.7","1.7.1","1.7.2","1.7.M01","1.7.M02","1.7.M03","1.8","1.8.1","1.8.2","1.8.3","1.8.M01","1.8.M02","1.8.M03","1.8.M04","1.8.M05","1.8.M06","1.8.M07","1.8.RC1","1.9","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","1.9.M01","1.9.M02","1.9.M03","1.9.M04","1.9.M05","1.9.RC1","1.9.RC2","2.0.0","2.0.0-M01","2.0.0-M02","2.0.0-M03","2.0.0-M04","2.0.0-M05","2.0.0-M06","2.0.0-RC1","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.0-M01","2.1.0-M02","2.1.0-RC1","2.1.0-RC2","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.2.0","2.2.0-M01","2.2.0-M02","2.2.0-M03","2.2.0-M04","2.2.0-RC01","2.2.1","2.2.10","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","2.3.0","2.3.0-M01","2.3.0-M02","2.3.0-M03","2.3.0-RC1","2.3.1","2.3.10","2.3.11","2.3.12","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2025.01.0","2025.02.0","2025.03.0","2025.04.0","2025.05.0","2025.05.1","2025.06.0","2025.06.1","2025.06.2","2025.07.0","2025.07.1","2025.08.0","2025.09.0","2025.10.1","2025.11.2","2025.12.1","3.0.0","3.0.0-M01","3.0.0-M02","3.0.0-M03","3.0.0-M04","3.0.0-M05","3.0.0-RC1","3.0.1","3.0.10","3.0.11","3.0.12","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.0-BETA1","3.1.0-M01","3.1.0-M02","3.1.0-M03","3.1.0-M04","3.1.0-M05","3.1.0-M06","3.1.0-M07","3.1.0-M08","3.1.0-M09","3.1.0-M10","3.1.0-M12-beta2","3.1.0-M13-beta3","3.1.0-RC1","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.2.0","3.2.0-alpha01","3.2.0-alpha02","3.2.0-alpha03","3.2.0-alpha04","3.2.0-alpha05","3.2.0-alpha06","3.2.0-alpha07","3.2.0-alpha08","3.2.0-rc1","3.2.0-rc2","3.2.0-rc3","3.2.1","3.2.10","3.2.11","3.2.12","3.2.13","3.2.14","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3.0","3.3.0-alpha01","3.3.0-alpha02","3.3.0-alpha03","3.3.0-alpha04","3.3.0-alpha05","3.3.0-alpha06","3.3.0-alpha07","3.3.0-beta01","3.3.0-beta02","3.3.0-rc1","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9","3.4.0","3.4.0-alpha01","3.4.0-alpha02","3.4.0-alpha03","3.4.0-alpha04","3.4.0-alpha05","3.4.0-alpha06","3.4.0-alpha07","3.4.0-alpha08","3.4.0-alpha09","3.4.0-alpha10","3.4.0-beta01","3.4.0-beta02","3.4.0-rc01","3.4.0-rc02","3.4.1","3.4.10","3.4.11","3.4.12","3.4.13","3.4.14","3.4.15","3.4.16","3.4.17","3.4.18","3.4.3","3.4.4","3.4.5","3.4.6","3.4.7","3.4.8","3.4.9","3.5.0","3.5.0-alpha01","3.5.0-alpha02","3.5.0-alpha03","3.5.0-alpha04","3.5.0-alpha05","3.5.0-alpha06","3.5.0-alpha07","3.5.0-alpha08","3.5.0-alpha09","3.5.0-beta01","3.5.0-beta02","3.5.0-beta03","3.5.0-rc01","3.5.1","3.5.10","3.5.11","3.5.12","3.5.13","3.5.14","3.5.15","3.5.16","3.5.17","3.5.18","3.5.19","3.5.2","3.5.20","3.5.21","3.5.22","3.5.23","3.5.24","3.5.25","3.5.26","3.5.27","3.5.28","3.5.29","3.5.3","3.5.30","3.5.31","3.5.32","3.5.33","3.5.34","3.5.35","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8","3.5.9","4.0.0","4.0.0-rc01","4.0.1","4.0.10","4.0.11","4.0.12","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.1","4.1.10","4.1.11","4.1.12","4.1.13","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9","4.2.0","4.2.1","4.2.10","4.2.11","4.2.12","4.2.13","4.2.14","4.2.15","4.2.16","4.2.17","4.2.18","4.2.19","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9","4.3.0","4.3.1","4.3.10","4.3.11","4.3.12","4.3.13","4.3.14","4.3.15","4.3.16","4.3.17","4.3.18","4.3.19","4.3.2","4.3.20","4.3.21","4.3.22","4.3.23","4.3.24","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7","4.3.8","4.3.9","4.4.0","4.4.1","4.4.10","4.4.11","4.4.12","4.4.13","4.4.14","4.4.15","4.4.16","4.4.17","4.4.18","4.4.19","4.4.2","4.4.20","4.4.21","4.4.22","4.4.23","4.4.24","4.4.25","4.4.26","4.4.27","4.4.28","4.4.29","4.4.3","4.4.30","4.4.31","4.4.32","4.4.33","4.4.34","4.4.35","4.4.36","4.4.37","4.4.38","4.4.39","4.4.4","4.4.40","4.4.41","4.4.42","4.4.43","4.4.44","4.4.45","4.4.46","4.4.47","4.4.48","4.4.5","4.4.6","4.4.7","4.4.8","4.4.9","5.1.0","5.10.0","5.11.0","5.12.0","5.13.0","5.14.0","5.15.0","5.16.0","5.17.0","5.18.0","5.18.1","5.19.0","5.2.0","5.20.0","5.21.0","5.21.2","5.22.0","5.23.0","5.24.0","5.24.1","5.24.2","5.25.1","5.26.0","5.26.1","5.26.10","5.26.11","5.26.12","5.26.13","5.26.14","5.26.15","5.26.16","5.26.17","5.26.18","5.26.19","5.26.2","5.26.20","5.26.21","5.26.22","5.26.23","5.26.24","5.26.25","5.26.26","5.26.27","5.26.28","5.26.29","5.26.3","5.26.30","5.26.4","5.26.5","5.26.6","5.26.7","5.26.8","5.26.9","5.3.0","5.4.0","5.5.0","5.6.0","5.7.0","5.8.0","5.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xr72-g735-4vwp/GHSA-xr72-g735-4vwp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P"}]}