What is CVE-2026-67196?
CVE-2026-67196 is a Cross-Site Scripting vulnerability in the built-in Debug plugin of Perspective 5.0.0. Attackers can inject arbitrary HTML and JavaScript by writing table cell values with unescaped HTML markup, which is directly inserted into innerHTML during CSV serialization rendering. Users should apply the patch immediately.
Azərbaycanca: CVE-2026-67196, Perspective 5.0.0 versiyasının daxili Debug plaginində aşkarlanmış Cross-Site Scripting zəifliyidir. Təcavüzkar, CSV serializasiyası zamanı innerHTML-ə birbaşa əlavə olunan qaçırılmamış HTML işarələməsini cədvəl xanasına yazaraq ixtiyari HTML və JavaScript kodu yeridə bilər. İstifadəçilərə dərhal patchi tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which version of Perspective is affected by CVE-2026-67196?
CVE-2026-67196 was discovered in the built-in Debug plugin of Perspective version 5.0.0.
What can an attacker do by exploiting CVE-2026-67196?
Attackers can inject arbitrary HTML and JavaScript by writing table cell values with unescaped HTML markup, which is directly inserted into innerHTML during CSV serialization rendering.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.