CVE-2026-1337
ADVISORY - githubSummary
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.
Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
Common Weakness Enumeration (CWE)
Improper Output Neutralization for Logs
Improper Output Neutralization for Logs
NIST
2.3
CVSS SCORE
1.1lowGitHub
-
CVSS SCORE
1.1lowAlpine
-
Bitnami
BIT-neo4j-2026-1337
-
CVSS SCORE
1.1lowminimos
MINI-2j72-cw9j-vw22
-
minimos
MINI-73hp-j53f-6j47
-
minimos
MINI-9c4m-h2x2-hrx9
-
minimos
MINI-cpg3-6j8q-6xwf
-
minimos
MINI-fjqp-r56f-m7pw
-
minimos
MINI-j74q-98cq-ph4q
-
minimos
MINI-q848-xx3m-cm58
-
minimos
MINI-rh75-rr4w-5fcq
-
minimos
MINI-wgv5-x6qq-2839
-
minimos
MINI-wwrp-m64g-3m4x
-