CVE-2026-9029
Stored XSS via Geomap Panel Template Variable Attribution Injection
5.4
MEDIUM
CVSS 3.1
EPSS 0.25%
描述
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix
如何修補 CVE-2026-9029
要修補 CVE-2026-9029,請將受影響套件升級到下列已修補版本。
- —升級至 12.4.1 或更新版本
CVE-2026-9029 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 12.4.0, < 12.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |