Remote Code Execution Vulnerability in locize Localization Platform
CVE-2026-41886

7.5HIGH

Key Information:

Vendor

Locize

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-41886?

The locize Client SDK prior to version 4.0.21 is susceptible to a vulnerability that allows an attacker to exploit message events without proper validation of the event origin. Specifically, the SDK fails to restrict the dispatching of internal handlers based on trustworthy event origins. This oversight leaves the system exposed to potential exploitation through inadequately protected message events, permitting the execution of unintended actions in the application. This vulnerability has been addressed in version 4.0.21, and users are encouraged to upgrade to mitigate potential security risks.

Affected Version(s)

locize < 4.0.21

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.