SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23929

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A prototype pollution vulnerability in the searchParamsToObject() function allows for persistent cross-site scripting (XSS) attacks in Maps by failing to filter dangerous properties such as __proto__. This issue arises from the unsafe handling of URL parameters and jQuery's element creation, which can lead to unauthorized script execution. Organizations utilizing affected products should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-23929
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.

Related CVEs

Other vulnerabilities affecting the same vendor(s)