Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jfrq-hj9f-c8qx | CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage |
Thu, 16 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DOM‑based Cross‑Site Scripting via Window.postMessage in CleverTap Web SDK Visual Builder |
Tue, 03 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clevertap clevertap Web Sdk
|
|
| CPEs | cpe:2.3:a:clevertap:clevertap_web_sdk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clevertap clevertap Web Sdk
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clevertap
Clevertap web Sdk |
|
| Vendors & Products |
Clevertap
Clevertap web Sdk |
Fri, 27 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 CWE-829 |
|
| Metrics |
cvssV3_1
|
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-27T19:39:16.900Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26862
Updated: 2026-02-27T19:37:17.397Z
Status : Analyzed
Published: 2026-02-27T18:16:12.163
Modified: 2026-03-03T18:44:20.997
Link: CVE-2026-26862
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:00:13Z
Github GHSA