CVE-2026-40541
largeCross-Site Scripting in Synology Chat Server Enables Arbitrary File Access on DSM
Synology Chat Server before 2.4.5-22148 fails to properly neutralize input during web page generation, producing a cross-site scripting (CWE-79) flaw in its extract domain component. A remote authenticated user can trigger it through a UI interaction, and because the CVSS scope is changed, the injected script executes in the context of the underlying DSM system rather than only within Chat Server. Successful exploitation allows the attacker to read or write arbitrary files on DSM and to cause denial-of-service conditions, consistent with the critical 9.0 CVSS score carrying high confidentiality, integrity, and availability impact. Any Synology NAS running an affected Chat Server package is affected, although exploitation requires valid credentials and user interaction. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates roughly a 0.5% chance of exploitation within 30 days.
What to do: Upgrade Synology Chat Server to 2.4.5-22148 or later via DSM Package Center. Until patched, restrict Chat Server access to trusted authenticated users and minimize their DSM privileges, since exploitation requires valid credentials and a user interaction. Check DSM for unexplained file changes or service disruptions as indicators of exploitation.
| Synology Chat Server | before 2.4.5-22148 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.