A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.

Project Subscriptions

Vendors Products
Trimble Subscribe
Sketchup Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 May 2026 01:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.
Title Cross-Site Scripting in SketchUp Dynamic Components
First Time appeared Trimble
Trimble sketchup
CPEs cpe:2.3:a:trimble:sketchup:*:*:*:*:*:*:*:*
Vendors & Products Trimble
Trimble sketchup
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Bugcrowd

Published:

Updated: 2026-05-22T01:04:03.699Z

Reserved: 2026-05-22T00:57:32.121Z

Link: CVE-2026-9264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-22T02:16:35.073

Modified: 2026-05-22T02:16:35.073

Link: CVE-2026-9264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T02:30:15Z

Weaknesses

No weakness.