{"id":"CVE-2026-85061","summary":"MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip","details":"MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the attribution control inserts the content into innerHTML. A victim must render the affected map content for the script to execute. This issue is fixed in version 6.4.1.","aliases":["GHSA-jrc7-96c5-q579"],"modified":"2026-09-06T03:30:54.623736414Z","published":"2026-09-03T20:18:50.854Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85061.json"},"references":[{"type":"WEB","url":"https://github.com/maplibre/maplibre-gl-js/releases/tag/v6.4.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85061.json"},{"type":"ADVISORY","url":"https://github.com/maplibre/maplibre-gl-js/security/advisories/GHSA-jrc7-96c5-q579"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85061"},{"type":"FIX","url":"https://github.com/maplibre/maplibre-gl-js/commit/1da69f3cd913a39fa948708e01478663bf48bc27"},{"type":"FIX","url":"https://github.com/maplibre/maplibre-gl-js/pull/8189"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maplibre/maplibre-gl-js","events":[{"introduced":"0"},{"fixed":"1da69f3cd913a39fa948708e01478663bf48bc27"},{"fixed":"37e08c1901bee38fb5103510436b590c0460b44f"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"6.4.1"}]}}],"versions":["v6.4.0","v6.3.0","v6.2.0","v6.1.0","v6.0.0","v6.0.0-22","v6.0.0-21","v6.0.0-20","v6.0.0-19","v6.0.0-18","v6.0.0-17","v6.0.0-16","v6.0.0-15","v6.0.0-14","v6.0.0-13","v6.0.0-12","v6.0.0-11","v6.0.0-10","v6.0.0-9","v6.0.0-8","v6.0.0-7","v6.0.0-6","v6.0.0-5","v6.0.0-4","v6.0.0-3","v6.0.0-2","v6.0.0-1","v6.0.0-0","v5.24.0","v5.23.0","v5.22.0","v5.21.1","v5.21.0","v5.20.2","v5.20.1","v5.20.0","v5.19.0","v5.18.0","v5.17.0","v5.16.0","v5.15.0","v5.14.0","v5.13.0","v5.12.0","v5.11.0","v5.10.0","v5.9.0","v5.8.0","v5.7.3","v5.7.2","v5.7.1","v5.7.0","v5.6.2","v5.6.1","v5.6.0","v5.5.0","v5.4.0","v5.3.1","v5.3.0","v5.2.0","v5.1.1","v5.1.0","v5.0.1","v5.0.0","v5.0.0-pre.10","v5.0.0-pre.9","v5.0.0-pre.8","v5.0.0-pre.7","v5.0.0-pre.6","v5.0.0-pre.5","v5.0.0-pre.4","v5.0.0-pre.3","v5.0.0-pre.2","v5.0.0-pre.1","v4.7.1","v4.7.0","v4.6.0","v4.5.2","v4.5.1","v4.5.0","v4.4.1","v4.4.0","v4.3.2","v4.3.1","v4.3.0","v4.2.0","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.2","v4.0.1","v4.0.0","v4.0.0-pre.6","v4.0.0-pre.5","v4.0.0-pre.4","v4.0.0-pre.3","v4.0.0-pre.2","v4.0.0-pre.1","v3.6.2","v3.6.1","v3.6.0","v3.5.2","v3.5.1","v3.5.0","v3.4.1","v3.4.0","v3.3.1","v3.3.0","v3.2.2","v3.2.1","v3.2.0","v3.2.0-pre.3","v3.2.0-pre.2","v3.2.0-pre.1","v3.1.0","v3.0.1","v3.0.0","v3.0.0-pre.9","v3.0.0-pre.8","v3.0.0-pre.7","v3.0.0-pre.6","v3.0.0-pre.5","v3.0.0-pre.4","v3.0.0-pre.3","v3.0.0-pre.2","v3.0.0-pre.1","v3.0.0-pre.0","v2.4.0","v2.3.1-pre.2","v2.3.1-pre.1","v2.3.0","v2.2.1","v2.2.0","v2.2.0-pre.4","v2.2.0-pre.3","v2.2.0-pre.2","v2.2.0-pre.1","v2.1.9","v2.1.8","v2.1.8-pre.3","v2.1.8-pre.2","v2.1.8-pre.1","v2.1.7","v2.1.6","v2.1.6-pre.1","v2.1.5","v2.1.5-pre.1","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0","v2.0.0-pre.6","v2.0.0-pre.5","v2.0.0-pre.4","v2.0.0-pre.3","v2.0.0-pre.2","v2.0.0-pre.1","v1.15.2","v1.15.1","v1.15.0","v1.14.1-rc.2","v1.14.0","v1.14.0-rc.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85061.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}