{"id":"CVE-2026-85061","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-85061","summary":"MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes()…","details":"MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the attribution control inserts the content into innerHTML. A victim must render the affected map content for the script to execute. This issue is fixed in version 6.4.1.","published":"2026-09-03T21:17:23.323","modified":"2026-09-03T21:17:23.323","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/maplibre/maplibre-gl-js/commit/1da69f3cd913a39fa948708e01478663bf48bc27","label":"maplibre/maplibre-gl-js@1da69f3"},"references":[{"type":"WEB","url":"https://github.com/maplibre/maplibre-gl-js/commit/1da69f3cd913a39fa948708e01478663bf48bc27"},{"type":"WEB","url":"https://github.com/maplibre/maplibre-gl-js/pull/8189"},{"type":"WEB","url":"https://github.com/maplibre/maplibre-gl-js/releases/tag/v6.4.1"},{"type":"WEB","url":"https://github.com/maplibre/maplibre-gl-js/security/advisories/GHSA-jrc7-96c5-q579"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T21:17:23.323"}}