Sonatype Nexus Repository 3 Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Sonatype Nexus Repository versions 3.0.0 prior to 3.90.2. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in the context of a victim's browser by sending a specially crafted URL. Exploitation of this vulnerability requires user interaction, as the victim must click on the malicious link.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject and execute malicious JavaScript in the victim's browser.

Remediation

Users are advised to upgrade to Sonatype Nexus Repository version 3.91.0 or later. The latest version can be downloaded from the Sonatype Nexus Repository Downloads page.

Added: Apr 9, 2026, 12:24 AM
Updated: Apr 9, 2026, 12:24 AM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
1.7
exploitability
6.2
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.