CVE-2026-7308 — An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via t — CVE Database · The Intelligence Room