CVE-2025-69993Disclosure(leafletjs / leaflet)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch leafletjs leaflet systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • leaflet

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
leaflet

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-19: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-04-19: 1Technical Details · 2026-07-07: 104-1907-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ravindra Sirvi@ravindra_sirvi
    Disclosure

    @LeafletJS 🚨 Your library has a reported XSS vulnerability (CVE-2025-69993 / Snyk) in versions up to 1.9.4 via bindPopup() – malicious HTML/event handlers can execute in popups. Many apps (including ours) rely heavily on Leaflet maps. Please release a stable patched version soon

    Post summary

    The tweet announces an XSS flaw in LeafletJS (CVE‑2025‑69993) affecting versions up to 1.9.4, calling for a prompt patch release.

    0000039
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69993 Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTM… https://www.cve.org/CVERecord?id=CVE-2025-69993

    Post summary

    This post announces a newly disclosed XSS vulnerability in Leaflet’s bindPopup() method that affects versions up to 1.9.4, providing key technical details but no exploitation or mitigation information.

    00000177
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appleafletjsleaflet-node.js-

Explore more