Synology · Synology Chat Server · CVE-2026-40541
**Name of the Vulnerable Software and Affected Versions**
Synology Chat Server versions prior to 2.4.5-22148
**Description**
An improper neutralization of input during web page generation, known as Cross-site Scripting (XSS), occurs in the extract domain component. This allows remote authenticated users, through UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. This issue may also expose users to session theft, credential compromise, or unauthorized actions within the application.
**Recommendations**
Update Synology Chat Server to version 2.4.5-22148 or later.
Restrict access to administrative interfaces.
Monitor for unusual login activity or suspicious chat content.
Educate users to avoid clicking unexpected links or embedded content.