{"id":"CVE-2026-1337","aliases":["BIT-neo4j-enterprise-2026-1337","GHSA-xr72-g735-4vwp"],"url":"https://o3.security/vulnerability/CVE-2026-1337","summary":"Insufficient escaping of unicode characters in query log","details":"Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.\n\nProof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337","published":"2026-02-26T15:16:17.899Z","modified":"2026-09-10T16:01:43.970195073Z","cvss":null,"epss":{"score":0.00232,"percentile":0.14262,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Bitnami","name":"neo4j","fixedVersion":"2026.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/JoakimBulow/CVE-2026-1337"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1337"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T16:01:43.970195073Z"}}