Loading market data...
← Back to CVE feed

CVE-2026-23929

UNKNOWN View on NVD ↗

Description

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.

Published: Aug 18, 2026 13:17 UTC Modified: Aug 18, 2026 14:17 UTC