Intel

AIKIDO-2026-11158

spring-core is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-41845 Published Yesterday

71

High Risk

This Affects:

JAVAspring-core
5.3.0 - 5.3.48
Fixed in 5.3.49
6.1.0 - 6.1.27
Fixed in 6.1.28
6.2.0 - 6.2.18
Fixed in 6.2.19
7.0.0 - 7.0.7
Fixed in 7.0.7.1
Are you affected? Scan for Free

TL;DR

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-core is vulnerable to Cross-site Scripting (XSS) in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7.

How to fix this

Upgrade the org.springframework:spring-core library to the patch version.