<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Maps-Ng - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/maps-ng/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 13:40:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/maps-ng/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Scripting Vulnerability in Element maps-ng</title><link>https://feed.craftedsignal.io/briefs/2026-08-element-xss/</link><pubDate>Thu, 27 Aug 2026 13:40:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-element-xss/</guid><description>A stored cross-site scripting (XSS) vulnerability in the si-map component of Element maps-ng allows unauthenticated attackers to execute arbitrary scripts in a victim's browser via crafted map pin tooltips.</description><content:encoded><![CDATA[<p>Element maps-ng is affected by a high-severity cross-site scripting (XSS) vulnerability tracked as CVE-2026-66155. The flaw resides in the 'si-map' component, specifically within the handling of the 'points' property responsible for rendering tooltip labels on map pins. Due to the failure to properly neutralize user-controllable input, an attacker can supply malicious payloads as part of the map data. When a user interacts with a map containing these pins, specifically by hovering over them, the browser executes the injected JavaScript code. This vulnerability impacts versions V47, V48, and V49 of the product, with fixed versions identified as V47.12.3, V48.11.3, and V49.16.1 respectively. Successful exploitation enables session hijacking, unauthorized actions on behalf of the user, or redirection to malicious sites.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 7.6. Impacted organizations using vulnerable versions of maps-ng to display interactive maps may be susceptible to account takeover or information theft if users with high-level access interact with manipulated map pins. Given the nature of XSS, the attack is silent to the user and operates within the security context of the affected web application.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch Element maps-ng to the identified safe versions (V47.12.3, V48.11.3, or V49.16.1) immediately to address CVE-2026-66155.</li>
<li>Implement or update Content Security Policy (CSP) headers on web servers hosting maps-ng to restrict the execution of inline scripts and unauthorized external resources.</li>
<li>Audit web application logs for HTTP requests containing abnormal script characters or excessive payload lengths directed toward the si-map data endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>patch-management</category></item></channel></rss>