CVE-2026-28499Disclosure(vapor / leafkit)

LOWCVSS 6.1 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch vapor leafkit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped. Version 1.14.2 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-80CWE-116

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • leafkit

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
leafkit

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-18: 4Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 303-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Attention developers using LeafKit! 🚨 An XSS vulnerability (CVE-2026-28499) affects all versions prior to 1.14.2. Upgrade now to secure your applications! 🛡️ Review your templates and sanitize inputs to avoid risks! 🔗 https://www.tenable.com/cve/CVE-2026-28499 #CyberSecurity #XSS #DevOps

    Post summary

    The post alerts LeafKit developers to an XSS vulnerability (CVE-2026-28499) in pre‑1.14.2 releases, urging an upgrade and input sanitization to mitigate the risk.

    0000044
    258 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-28499 📊 Severity: 6.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28499 #CVE-2026-28499 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/4HcMXOxjMp

    Post summary

    The tweet announces CVE-2026-28499 with a medium severity score but provides no technical details, exploitation evidence, or remediation guidance.

    0000033
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28499 LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a collection (Array … https://www.cve.org/CVERecord?id=CVE-2026-28499

    Post summary

    The text announces CVE‑2026‑28499, describing an HTML escaping flaw in LeafKit’s templating language that occurs before version 1.14.2.

    0000091
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28499 XSS Vulnerability in LeafKit Templating Language Prior to Version 1.14.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28499

    Post summary

    A new XSS flaw (CVE‑2026‑28499) impacting LeafKit templating language versions before 1.14.2 is identified; detailed technical info is available but no PoC, exploit, or patch is referenced.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvaporleafkit---

Explore more