PT-2026-32628 · Debian+3 · Leaflet

CVE-2025-69993

·

Published

2026-04-14

·

Updated

2026-07-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Leaflet versions prior to 1.9.5
Description Cross-Site Scripting (XSS) occurs via the bindPopup() function. This function renders user-supplied input as raw HTML without sanitization, which allows the injection of arbitrary JavaScript code through event handler attributes. The malicious script executes in the context of the victim's browser session when they view an affected map popup.
Recommendations Update to version 1.9.5 or later. As a temporary workaround, consider restricting the use of the bindPopup() function until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69993

Affected Products

Leaflet