Skip to content
GoogleGHSA-3vq3-92v4-j6mf

Google: remote code execution

Critical9.8CVE-2026-35178 · Published May 28, 2026

### Summary Workbench https://workbench.developerforce.com, a popular open-source Salesforce administration tool (all versions up to 53.0.0), contains critical Remote Code Execution (RCE) and Cross-Site Scripting (XSS) vulnerabilities (assigned CVE-2026-35178). The XSS vulnerability is pre-authentication and can be used to write a malicious cookie. This cookie initializes the RCE exploit, which triggers once an authenticated user accesses specific pages that format timestamps. Furthermore, because Workbench stores users' OAuth tokens in session, attackers can leverage these vulnerabilities to hijack sessions and deploy persistent Apex backdoors to any Salesforce organization managed by the affected administrator. ### Severity CRITICAL #### Motivation This vulnerability is classified as CRITICAL due to the high ease of exploit delivery, the potential for low-privilege escalation, and the catastrophic downstream impact (blast radius). • Pre-authentication Delivery: The Reflected XSS allows exploits to be staged stealthily before a user even authenticates, such as via hidden iFrames. • Low-Privilege Escalation: An attacker with a standard, low-privilege Salesfo...

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/kopia/kopia
Go
< 0.23.00.23.0
Details and references

### Summary Workbench https://workbench.developerforce.com, a popular open-source Salesforce administration tool (all versions up to 53.0.0), contains critical Remote Code Execution (RCE) and Cross-Site Scripting (XSS) vulnerabilities (assigned CVE-2026-35178). The XSS vulnerability is pre-authentication and can be used to write a malicious cookie. This cookie initializes the RCE exploit, which triggers once an authenticated user accesses specific pages that format timestamps. Furthermore, because Workbench stores users' OAuth tokens in session, attackers can leverage these vulnerabilities to hijack sessions and deploy persistent Apex backdoors to any Salesforce organization managed by the affected administrator. ### Severity CRITICAL #### Motivation This vulnerability is classified as CRITICAL due to the high ease of exploit delivery, the potential for low-privilege escalation, and the catastrophic downstream impact (blast radius). • Pre-authentication Delivery: The Reflected XSS allows exploits to be staged stealthily before a user even authenticates, such as via hidden iFrames. • Low-Privilege Escalation: An attacker with a standard, low-privilege Salesforce trial account can authenticate to a Workbench instance (including the public Developerforce deployment hosting ~200, 000 monthly active users) and exploit the RCE to escalate privileges. • Downstream Compromise: Once RCE is achieved, the attacker can harvest Salesforce OAuth tokens stored in session and deploy per

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Google advisories

All Google
Advisory
Google Chrome: out-of-bounds write
High8.8Jul 1
Google Chrome: buffer overflow
High8.8Jul 1
Google Chrome: out-of-bounds read
Medium6.5Jul 1
Google Chrome: remote code execution
High8.8Jul 1
Google Chrome: remote attacker could potentially perform a sandbox escape
Critical9.6Jul 1
Google Chrome: spoofing
Medium6.5Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.