THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3wgp-x9p5-c7cc (medium) — Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

[GHSA] GHSA-3wgp-x9p5-c7cc (medium) — Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

medgithub_advisoriesPublished 2026-09-01

GHSA-3wgp-x9p5-c7cc Severity: medium CVE: CVE-2026-58191

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

## Summary

Appium's base-driver mounts the built-in `/test/guinea-pig`, `/test/guinea-pig-scrollable` and `/test/guinea-pig-app-banner` routes **unconditionally** on every server. The handler reflects the `throwError` query param, the `comments` POST fiel

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3wgp-x9p5-c7cc