Intel

AIKIDO-2026-10641

context-mode is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 29, 2026

56

Medium Risk

This Affects:

JScontext-mode
1.0.81 - 1.0.89
Fixed in 1.0.90
Are you affected? Scan for Free

TL;DR

The search results page rendered r.highlighted directly into the DOM using dangerouslySetInnerHTML without escaping/sanitization. If r.highlighted could be influenced by indexed or backend content, this enables HTML/JS injection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

context-mode is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.81 - 1.0.89.

How to fix this

Upgrade the context-mode library to the patch version.