Subject: PSA-2026-00016-1: Stored XSS in VM notes field
Advisory date: 2026-04-24
Packages: pve-manager, proxmox-yew-comp, proxmox-datacenter-manager-ui
Details:
Missing sanitation of the <base> HTML tag when encoding the VM notes field could be exploited to execute arbitrary JS code in the...