CVE-2026-1337
EUVD-2026-568306.02.2026, 14:16
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| neo4j | neo4j | 𝑥 < 2026.01 |
| neo4j | neo4j | 𝑥 < 2026.01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration