Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5mf-6rh3-rhgg | CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function |
Thu, 16 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via Improper Origin Validation in CleverTap Web SDK |
Tue, 03 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clevertap clevertap Web Sdk
|
|
| CPEs | cpe:2.3:a:clevertap:clevertap_web_sdk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clevertap clevertap Web Sdk
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clevertap
Clevertap web Sdk |
|
| Vendors & Products |
Clevertap
Clevertap web Sdk |
Fri, 27 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| Metrics |
cvssV3_1
|
Fri, 27 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-27T19:42:58.097Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26861
Updated: 2026-02-27T19:41:16.290Z
Status : Analyzed
Published: 2026-02-27T18:16:12.043
Modified: 2026-03-03T18:46:02.547
Link: CVE-2026-26861
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:00:13Z
Github GHSA