
@LeafletJS 🚨 Your library has a reported XSS vulnerability (CVE-2025-69993 / Snyk) in versions up to 1.9.4 via bindPopup() – malicious HTML/event handlers can execute in popups. Many apps (including ours) rely heavily on Leaflet maps. Please release a stable patched version soon
Post summary
The tweet announces an XSS flaw in LeafletJS (CVE‑2025‑69993) affecting versions up to 1.9.4, calling for a prompt patch release.

