Unrated severityNVD Advisory· Published Aug 4, 2026· Updated Aug 4, 2026
SNOMED International Snowstorm reflected XSS
CVE-2026-66300
Description
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.
Affected products
2- Range: <10.12.2, <10.9.3
Patches
Vulnerability mechanics
References
4- github.com/IHTSDO/snowstorm/commit/575b555695811110dafe2fcea7dd2fd7e4bcee39mitrepatch
- github.com/IHTSDO/snowstorm/commit/b8061add427c930b3030549e77aa23ec5957ceb6mitrepatch
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-212-01.jsonmitrethird-party-advisory
- www.cve.org/CVERecordmitrevdb-entry
News mentions
0No linked articles in our index yet.