← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 20:18via CVEFeed

CVE-2026-85061 - MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

Brief

CVE ID : CVE-2026-85061

Published : Sept. 3, 2026, 8:18 p. m.

  • 21 minutes ago

Description : MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.

  • 1, DOM. sanitize() in src/util/dom. ts iterates elem. attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute.

An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the attribution control inserts the content into innerHTML. A victim must render the affected map content for the script to execute. This issue is fixed in version 6.

  • 1.
Read more on CVEFeed