{"id":"UBUNTU-CVE-2025-69993","details":"Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., \u003cimg src=x onerror=\"alert('XSS')\"\u003e). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.","modified":"2026-05-20T16:23:50.801041224Z","published":"2026-04-14T15:16:00Z","upstream":["CVE-2025-69993"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-69993"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-69993"},{"type":"REPORT","url":"https://github.com/PierfrancescoConti/leaflet-cve-2025-69993/blob/main/ADVISORY.md"},{"type":"REPORT","url":"http://leaflet.com"}],"affected":[{"package":{"name":"leaflet","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.3~dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"0.7.3~dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.7+20160312-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"0.7.7+20160312-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.1~dfsg-1","1.5.1~dfsg-2","1.6.0~dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"1.6.0~dfsg-1"},{"binary_name":"node-leaflet","binary_version":"1.6.0~dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.1~dfsg-2","1.7.1~dfsg-4","1.7.1~dfsg-5","1.7.1~dfsg-6"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"1.7.1~dfsg-6"},{"binary_name":"node-leaflet","binary_version":"1.7.1~dfsg-6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.1~dfsg-7"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"1.7.1~dfsg-7"},{"binary_name":"node-leaflet","binary_version":"1.7.1~dfsg-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.1~dfsg-7"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-leaflet","binary_version":"1.7.1~dfsg-7"},{"binary_name":"node-leaflet","binary_version":"1.7.1~dfsg-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}},{"package":{"name":"leaflet","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/leaflet?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.1~dfsg-7","1.7.1~dfsg-7build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.7.1~dfsg-7build1","binary_name":"libjs-leaflet"},{"binary_name":"node-leaflet","binary_version":"1.7.1~dfsg-7build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-69993.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}