CVE-2026-66155: XSS

Published Aug 27, 2026
·
Updated

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session.

Affected Software

3 affected components
Element maps-ng>0<=47.11.3
Element/maps-ng>47.12.3<=48.11.2
Element/maps-ng>48.11.3<=49.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Element maps-ng (si-map) to a version that resolves this vulnerability.

    Fixed in V47.12.3
  2. Upgrade

    Upgrade Element maps-ng (si-map) to a version that resolves this vulnerability.

    Fixed in V48.11.3
  3. Upgrade

    Upgrade Element maps-ng (si-map) to a version that resolves this vulnerability.

    Fixed in V49.16.1

Event History

Aug 27, 2026
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Element maps-ng V47 before V47.12.3, V48 before V48.11.3, and V49 before V49.16.1 are affected. The issue is in the si-map component.

2

What must an attacker do to exploit this issue?

An attacker must craft a malicious URL containing controlled map-pin points data and convince a victim to load it. Script execution occurs when the victim hovers over the affected map pin's tooltip label.

3

Is authentication or user interaction required?

The attack vector is network-based and requires low privileges, but victim interaction is required. The victim must load the malicious URL and hover over the map pin.

4

What is the security impact if exploitation succeeds?

The attacker can execute arbitrary script in the victim's browser session. The provided severity vector indicates high confidentiality impact, low integrity impact, and no availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203