Cross-Site Scripting Vulnerability in MapLibre GL JS by MapLibre
CVE-2026-85061

10CRITICAL

Key Information:

Vendor

Maplibre

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85061?

MapLibre GL JS, a library for web-based interactive vector maps, has a vulnerability that allows attackers to exploit untrusted third-party style attribution strings. Prior to version 6.4.1, the DOM.sanitize() function mismanages attribute handling, resulting in the potential execution of malicious scripts. Specifically, aggressive attribute manipulation enables dangerous HTML attributes to bypass sanitization, leading to script execution when manipulated map content is rendered. Users must ensure they update to version 6.4.1 to mitigate this risk.

Affected Version(s)

maplibre-gl-js < 6.4.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.