Description
A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Console. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.1.10 is recommended to address this issue.
Recommendation
Update the @questdb/web-console package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.10
- Patched version(s): 1.1.10
References
Could your website be exposed too?
SmartScanner can check your website for QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler - CVE-2026-1721
- Svelte SSR vulnerable to cross-site scripting via spread attributes - CVE-2026-42599
- x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting - CVE-2022-25646


