CVE-2026-48167MEDIUMCVSS 6.4

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

Published Jun 23, 2026·Updated Jun 23, 2026

Description

The `ImageColumn` and `ImageEntry` components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an attacker could plant malicious HTML or JavaScript and achieve stored XSS that executes for users who view the table or schema.

Affected Packages (2)

filament/tablesCOMPOSER
From 4.0.0
Fixed in = 4.11.4
filament/infolistsCOMPOSER
From 4.0.0
Fixed in = 4.11.4

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free