PT-2026-57883 · Appium · Appium
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Appium versions prior to 1.85.10
Description
The
createLocatorGeneratorUI function fails to escape HTML or JavaScript context when interpolating element attributes—specifically text, content-desc, resource-id, and locator selector values—into an HTML template literal. An attacker controlling the UI of the application under test can inject arbitrary HTML and JavaScript into the MCP UI resource returned by the generate locators tool. When the MCP client renders this resource, the injected script executes and can invoke arbitrary MCP tools via window.parent.postMessage, enabling unauthorized actions such as taking screenshots or reading page source.Recommendations
Update to version 1.85.10.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appium