Back

HIGH

Prototype pollution leading to stored XSS

Published Aug 18, 2026

Description

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Aug 18, 2026
NVD
Status Analyzed
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Zabbix
Published Aug 18, 2026
Updated Aug 19, 2026
Exploited since n/a
EUVD-2026-60734