Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xr72-g735-4vwp | Neo4j Enterprise and Community editions have insufficient escaping of unicode characters in query log |
| Link | Providers |
|---|---|
| https://github.com/JoakimBulow/CVE-2026-1337 |
|
Tue, 24 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Neo4j neo4j
|
|
| CPEs | cpe:2.3:a:neo4j:neo4j:*:*:*:*:community:*:*:* cpe:2.3:a:neo4j:neo4j:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Neo4j neo4j
|
|
| Metrics |
cvssV3_1
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Neo4j
Neo4j community Edition Neo4j enterprise Edition |
|
| Vendors & Products |
Neo4j
Neo4j community Edition Neo4j enterprise Edition |
Fri, 06 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit: https://github.com/JoakimBulow/CVE-2026-1337 | |
| Title | Insufficient escaping of unicode characters in query log | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Neo4j
Published:
Updated: 2026-02-06T14:30:29.856Z
Reserved: 2026-01-22T13:14:55.461Z
Link: CVE-2026-1337
Updated: 2026-02-06T14:30:21.922Z
Status : Analyzed
Published: 2026-02-06T14:16:38.120
Modified: 2026-02-24T21:21:55.050
Link: CVE-2026-1337
No data.
OpenCVE Enrichment
Updated: 2026-04-17T22:45:29Z
Github GHSA