Cross-Site Scripting Vulnerability in DeepL Chrome Browser Extension
CVE-2026-40451

5.1MEDIUM

Key Information:

Vendor

Deepl

Vendor
CVE Published:
22 April 2026

What is CVE-2026-40451?

A cross-site scripting vulnerability has been identified in the DeepL Chrome browser extension, affecting versions v1.22.0 to v1.23.0. This flaw can potentially allow an attacker to execute arbitrary scripts within a user's browser session. Additionally, it opens the door for the injection of malicious HTML content into web pages viewed by users, posing significant security risks. Users of the affected versions should take immediate steps to update their extensions to safeguard against potential exploitation.

Affected Version(s)

Chrome browser extension from v1.22.0 to v.1.23.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.