ThreatCluster

Critical MapLibre GL JS Vulnerability Exposes Millions to Zero-Click Attacks

First seen 9 Sep 2026, 18:13 UTC GbhackersCybersecuritynews 71

Article Content

Browse articles
ThreatCluster

A critical cross-site scripting vulnerability, CVE-2026-85061, has been disclosed in the MapLibre GL JS library, affecting versions 6.4.0 and earlier. This flaw allows for potential zero-click attacks, putting approximately 2.7 million users at risk. The vulnerability is rooted in the DOM.sanitize() function, which fails to properly sanitize user input. Users are strongly advised to upgrade to version 6.4.1, which addresses this issue. The vulnerability was published on September 3, 2026, and is documented in GitHub advisory GHSA-jrc7-96c5-q579. The widespread use of MapLibre GL JS in web applications amplifies the potential impact of this flaw. Organizations utilizing this library should prioritize patching to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-85061 affects MapLibre GL JS versions 6.4.0 and earlier. • The vulnerability could expose 2.7 million users to zero-click attacks. • Users are urged to upgrade to version 6.4.1 to mitigate the risk.

Ask AI about this cluster

Timeline

2026-09-03
CVE-2026-85061 published
A critical cross-site scripting vulnerability in MapLibre GL JS was disclosed, affecting versions 6.4.0 and earlier.
Gbhackers
2026-09-09
Users advised to upgrade
MapLibre GL JS users are recommended to upgrade to version 6.4.1 to address the critical vulnerability.
Cybersecuritynews