GHSA-j5mf-6rh3-rhgg
HIGHCVE-2026-26861CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain.
- Affected
- < 1.15.3
- Fixed in
- 1.15.3
- Weakness
- CWE-79
- Published
- 2026-02-27
- Source
- github