A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.

Project Subscriptions

Vendors Products
Trimble Subscribe
Sketchup Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 May 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 22 May 2026 01:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.
Title Cross-Site Scripting in SketchUp Dynamic Components
First Time appeared Trimble
Trimble sketchup
CPEs cpe:2.3:a:trimble:sketchup:*:*:*:*:*:*:*:*
Vendors & Products Trimble
Trimble sketchup
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Bugcrowd

Published:

Updated: 2026-05-22T15:52:45.358Z

Reserved: 2026-05-22T00:57:32.121Z

Link: CVE-2026-9264

cve-icon Vulnrichment

Updated: 2026-05-22T15:49:55.552Z

cve-icon NVD

Status : Received

Published: 2026-05-22T02:16:35.073

Modified: 2026-05-22T02:16:35.073

Link: CVE-2026-9264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T03:00:12Z

Weaknesses