Threat Advisory

MapLibre GL JS Flaw Allows Attackers to Execute Zero-Click XSS Attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-85061 with a CVSS score of 10.0, affects applications that render untrusted map styles or custom attributions, allowing attackers to execute zero-click attacks by bypassing the DOM sanitizer function in Live NamedNodeMap Removal Skip via providing an HTML payload containing consecutive dangerous attributes. The sanitizer strips the first attribute while missing the second one, which executes upon insertion into innerHTML without requiring user input. This flaw enables attackers to hijack user sessions or steal sensitive data, posing a significant risk for any platform displaying third-party map data. Specifically, this vulnerability affects library versions prior to 6.4.1, and developers must update their web mapping applications immediately by upgrading to MapLibre GL JS version 6.4.1 or the latest release.

RECOMMENDATION:

We recommend you to update maplibre-gl to version 6.4.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-85061 with a CVSS score of 10.0, affects applications that render untrusted map styles or custom attributions, allowing attackers to execute zero-click attacks by bypassing the DOM sanitizer function in Live NamedNodeMap Removal Skip via providing an HTML payload containing consecutive dangerous attributes. The sanitizer strips the first attribute while missing the second one, which executes upon insertion into innerHTML without requiring user input. This flaw enables attackers to hijack user sessions or steal sensitive data, posing a significant risk for any platform displaying third-party map data. Specifically, this vulnerability affects library versions prior to 6.4.1, and developers must update their web mapping applications immediately by upgrading to MapLibre GL JS version 6.4.1 or the latest release.

RECOMMENDATION:

We recommend you to update maplibre-gl to version 6.4.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu