CVE-2026-66155: XSS
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Element maps-ng (si-map)to a version that resolves this vulnerability.Fixed in V47.12.3 - Upgrade
Upgrade
Element maps-ng (si-map)to a version that resolves this vulnerability.Fixed in V48.11.3 - Upgrade
Upgrade
Element maps-ng (si-map)to a version that resolves this vulnerability.Fixed in V49.16.1
Event History
Frequently Asked Questions
Which deployments are affected?
Element maps-ng V47 before V47.12.3, V48 before V48.11.3, and V49 before V49.16.1 are affected. The issue is in the si-map component.
What must an attacker do to exploit this issue?
An attacker must craft a malicious URL containing controlled map-pin points data and convince a victim to load it. Script execution occurs when the victim hovers over the affected map pin's tooltip label.
Is authentication or user interaction required?
The attack vector is network-based and requires low privileges, but victim interaction is required. The victim must load the malicious URL and hover over the map pin.
What is the security impact if exploitation succeeds?
The attacker can execute arbitrary script in the victim's browser session. The provided severity vector indicates high confidentiality impact, low integrity impact, and no availability impact.