
CVE-2026-31860 Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR… https://www.cve.org/CVERecord?id=CVE-2026-31860
Post summary
CVE-2026-31860 reveals that useHeadSafe() can be bypassed to inject arbitrary HTML attributes, enabling potential XSS or template injection via SSR.

