CVE-2026-0601

Publication date

2026-01-14 22:05:17

Family

Sonatype

State

PUBLISHED

Description

A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victims browser through a specially crafted request requiring user interaction.