Nexus Repository vulnerability

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

Published 8 Apr 2026Updated 18 Sep 20262 sources
CVSS 5.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.