Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-93432

MEDIUM NVD
CVSS Score 6.1
Severity MEDIUM
Published Sep 18, 2026
Vendor unknown

Description

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.

References