THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jrc7-96c5-q579 (critical) — MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

[GHSA] GHSA-jrc7-96c5-q579 (critical) — MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

medgithub_advisoriesPublished 2026-09-08

GHSA-jrc7-96c5-q579 Severity: critical CVE: CVE-2026-85061

MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

### Impact `DOM.sanitize()` in `src/util/dom.ts` iterated `elem.attributes` (a live `NamedNodeMap`) while calling `elem.removeAttribute()` in the same loop. Removing an attribute shifts subsequent attributes down by one index, causing the iterator t

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jrc7-96c5-q579