CVE-2026-79720
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
- Published Aug 27, 2026
- CVSS 6.8 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available