CVE-2026-76837 | Baserow prior 2.3.0 Renderer mention.js first_name cross site scripting (EUVD-2026-65009)

SecurityVulns

A vulnerability categorized as problematic has been discovered in Baserow prior 2.3.0. Affected by this issue is some unknown functionality of the file web-frontend/modules/core/editor/mention.js of the component Renderer. Executing a manipulation of the argument first_name can lead to cross site scripting.

This vulnerability is registered as CVE-2026-76837. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More