CVE-2026-58191
EUVD-2026-4242508.07.2026, 21:16
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError query parameter, comments POST field, and User-Agent request header into HTML without escaping, allowing reflected cross-site scripting and arbitrary JavaScript execution on the server origin. This issue is fixed in version 10.7.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| appium | appium/base-driver | 𝑥 < 10.7.0 |
𝑥
= Vulnerable software versions