ZeroHour

CVE-2026-40541

large

Cross-Site Scripting in Synology Chat Server Enables Arbitrary File Access on DSM

CVSS 3.1
9.0 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

Synology Chat Server before 2.4.5-22148 fails to properly neutralize input during web page generation, producing a cross-site scripting (CWE-79) flaw in its extract domain component. A remote authenticated user can trigger it through a UI interaction, and because the CVSS scope is changed, the injected script executes in the context of the underlying DSM system rather than only within Chat Server. Successful exploitation allows the attacker to read or write arbitrary files on DSM and to cause denial-of-service conditions, consistent with the critical 9.0 CVSS score carrying high confidentiality, integrity, and availability impact. Any Synology NAS running an affected Chat Server package is affected, although exploitation requires valid credentials and user interaction. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates roughly a 0.5% chance of exploitation within 30 days.

What to do: Upgrade Synology Chat Server to 2.4.5-22148 or later via DSM Package Center. Until patched, restrict Chat Server access to trusted authenticated users and minimize their DSM privileges, since exploitation requires valid credentials and a user interaction. Check DSM for unexplained file changes or service disruptions as indicators of exploitation.

Affected
Synology Chat Serverbefore 2.4.5-22148
Estimated exposure
largetens of thousands of Synology NAS deployments running the Chat Server package (estimated) — Synology's overall NAS installed base is in the millions and Chat Server is one of its commonly deployed productivity packages, so the affected subset is estimated at the order of tens of thousands of installations; exact package install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.