Cross-Site Scripting Vulnerability in MapLibre GL JS by MapLibre
CVE-2026-85061
10CRITICAL
What is CVE-2026-85061?
MapLibre GL JS, a library for web-based interactive vector maps, has a vulnerability that allows attackers to exploit untrusted third-party style attribution strings. Prior to version 6.4.1, the DOM.sanitize() function mismanages attribute handling, resulting in the potential execution of malicious scripts. Specifically, aggressive attribute manipulation enables dangerous HTML attributes to bypass sanitization, leading to script execution when manipulated map content is rendered. Users must ensure they update to version 6.4.1 to mitigate this risk.
Affected Version(s)
maplibre-gl-js < 6.4.1
