GHSA-3chg-m5w7-qfv5
HIGHCVE-2026-41845Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
- Affected
- >= 7.0.0, <= 7.0.7
- Fixed in
- 7.0.8
- Weakness
- CWE-79
- Published
- 2026-06-09
- Source
- github