Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-23929

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Aug 18, 2026
Vendor unknown

Description

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.

References