Bootstrap Cross-Site Scripting Vulnerability
A vulnerability in the Bootstrap framework allows for Cross-Site Scripting (XSS) attacks by an unauthenticated remote attacker, potentially leading to arbitrary script execution in a user's browser.
CVE search metadata
CVE search record: CVE-2019-8331. Severity: medium. CVSS: 6.1. EPSS: 16.40%. KEV: no. Product: Bootstrap (< 4.3.1). Brief: Bootstrap Cross-Site Scripting Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bootstrap-xss/
A security vulnerability (CVE-2019-8331) has been identified in the Bootstrap framework, specifically affecting versions prior to 4.3.1. This vulnerability allows a remote, unauthenticated attacker to conduct Cross-Site Scripting (XSS) attacks. By injecting malicious scripts into web applications that utilize vulnerable versions of Bootstrap, an attacker can execute code within the context of a victim's browser session. This can lead to session hijacking, credential theft, or the modification of web page content viewed by the user. Defenders should prioritize auditing web applications for these vulnerable versions of the Bootstrap framework and upgrade to version 4.3.1 or later to mitigate the risk.
Impact
Successful exploitation of this XSS vulnerability allows unauthorized actors to execute arbitrary scripts in the victim's browser. This poses a significant risk to the integrity and confidentiality of user data on affected web applications, potentially facilitating session hijacking or phishing attacks against users.
Recommendation
Prioritized actions for security and development teams:
- Audit all web applications to identify dependencies using Bootstrap versions prior to 4.3.1.
- Upgrade the Bootstrap framework to version 4.3.1 or later across all identified applications.
- Apply Content Security Policy (CSP) headers as a defense-in-depth measure to restrict the execution of unauthorized scripts.
Mitigations
Upgrade Bootstrap to 4.3.1 or later
CVE-2019-8331