CVE-2026-58191 with a CVSS score of 6.5 is a reflected cross-site scripting (XSS) vulnerability affecting @appium/base-driver versions <= 10.6.0 in Appium's base-driver, allowing an attacker to execute arbitrary JavaScript on the server's origin by getting a victim to open a crafted link or auto-submit a form to the Appium server. The vulnerability exists due to the unconditionally mounted routes and the lack of HTML/JS escaping in the returned HTML via compileLodashTemplate, which interpolates <%= expr %> as String(expr) with no escaping. This allows an attacker to drive the WebDriver REST API and plugin endpoints, which are debug/test fixtures that should not be reachable on a production listener at all, resulting in business impact including unauthorized access to sensitive data and potential exploitation of other vulnerabilities through the compromised server.
We recommend you to update @appium/base-driver to version 10.7.0.[/subscribe_to_unlock_form]
CVE-2026-58191 with a CVSS score of 6.5 is a reflected cross-site scripting (XSS) vulnerability affecting @appium/base-driver versions <= 10.6.0 in Appium's base-driver, allowing an attacker to execute arbitrary JavaScript on the server's origin by getting a victim to open a crafted link or auto-submit a form to the Appium server. The vulnerability exists due to the unconditionally mounted routes and the lack of HTML/JS escaping in the returned HTML via compileLodashTemplate, which interpolates <%= expr %> as String(expr) with no escaping. This allows an attacker to drive the WebDriver REST API and plugin endpoints, which are debug/test fixtures that should not be reachable on a production listener at all, resulting in business impact including unauthorized access to sensitive data and potential exploitation of other vulnerabilities through the compromised server.
We recommend you to update @appium/base-driver to version 10.7.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]