Zero‑Click XSS Flaw Discovered in MapLibre GL JS Prompts Immediate Upgrade
A critical cross‑site scripting (XSS) weakness identified as CVE‑2026‑85061 has been disclosed in the open‑source mapping library MapLibre GL JS. The flaw enables attackers to execute malicious scripts without any user interaction—a so‑called zero‑click attack—by exploiting a vulnerability in the library's handling of style data. The issue is documented in the GitHub advisory GHSA‑jrc7‑96c5‑q579, and developers are being urged to update their installations without delay.
The vulnerability resides in versions of MapLibre GL JS up to and including 6.4.0. By injecting crafted JSON payloads into map style definitions, an attacker can cause the library to render hostile JavaScript code directly in the browser context. Because the exploit does not require a user to click a link or otherwise engage with the malicious content, it bypasses many traditional defenses that rely on user‑initiated actions.
MapLibre GL JS is a widely adopted JavaScript library used to render interactive, vector‑based maps in web applications. It emerged as a community‑driven fork of Mapbox GL JS after licensing changes, and it powers countless sites ranging from news outlets to logistics dashboards. Any web page that embeds the library and loads external style sources is potentially exposed to the flaw, making the risk surface broad and the impact significant for developers who rely on the library for geospatial visualisation.
The flaw was initially reported by the security research group GBHackers, who filed the advisory on GitHub. The advisory outlines the technical details of the exploit and provides remediation steps. The maintainers have confirmed that the vulnerability is patched in releases issued after version 6.4.0, and they recommend that all projects upgrade to the latest stable version, audit any custom style configurations, and monitor for unexpected script execution in their environments.
The discovery underscores the growing importance of proactive security monitoring in open‑source software supply chains. As libraries like MapLibre GL JS become integral components of modern web infrastructure, timely vulnerability disclosure and rapid patch deployment are essential to protect end users. Stakeholders are advised to keep dependency management tools up to date, subscribe to security advisories, and consider automated testing for XSS vectors to mitigate similar risks in the future.
Comments (0)
Be the first to comment.
Join the discussion