CVE-2026-93432
MEDIUM
NVD
CVSS Score
6.1
Severity
MEDIUM
Published
Sep 18, 2026
Vendor
unknown
Description
A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.