Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape
A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands, but a polyglot payload bypasses the filter and achieves remote code execution.
PoC: CVE-2026-1337
CVE-2026-1337 - Neo4j - Log Injection
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free