
Critical MapLibre GL JS Flaw Allows Zero-Click XSS Attacks Without User Interaction
A critical vulnerability in MapLibre GL JS could allow attackers to execute zero-click cross-site scripting attacks through malicious map attribution content. Tracked as CVE-2026-85061 and GitHub Security Advisory GHSA-jrc7-96c5-q579, the flaw affects maplibre-gl versions 6.4.0 and earlier. MapLibre GL JS version 6.4.1 addresses the issue. The vulnerability resides in DOM.sanitize() within src/util/dom.ts, a function intended […]
The post Critical MapLibre GL JS Flaw Allows Zero-Click XSS Attacks Without User Interaction appeared first on Cyber Security News.