PT-2026-56608 · Appium · Appium
CVE-2026-58191
·
Published
2026-07-08
·
Updated
2026-09-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Appium versions prior to 10.7.0
Description
The base-driver unconditionally mounts the '/test/guinea-pig', '/test/guinea-pig-scrollable', and '/test/guinea-pig-app-banner' endpoints. The
compileLodashTemplate function reflects the throwError query parameter, comments POST field, and User-Agent request header into HTML without proper escaping. This allows reflected cross-site scripting (XSS), where malicious scripts are injected into trusted websites, and arbitrary JavaScript execution on the server origin.Recommendations
Update to version 10.7.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Appium