CVE-2026-40451Patch

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-23); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-23: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 2Technical Details · 2026-04-28: 104-2204-2304-28
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-232
Disclosure2
2026-04-281
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40451 DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in… https://www.cve.org/CVERecord?id=CVE-2026-40451

    Post summary

    CVE‑2026‑40451 is a cross‑site scripting flaw in the DeepL Chrome extension (v1.22.0–1.23.0). No PoC, exploit, or active exploitation is reported.

    00010324
    57.2K followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    DeepL Chrome Extension XSS Flaw CVE-2026-40451 - Update Now https://thecybrdef.com/deepl-chrome-extension-xss-cve-2026-40451/

    Post summary

    The article identifies an XSS vulnerability (CVE‑2026‑40451) in the DeepL Chrome Extension and urges users to update, indicating a patch is available.

    0000132
    6 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    DeepL Chrome Extension XSS Flaw CVE-2026-40451 – Update Now https://thecybrdef.com/deepl-chrome-extension-xss-cve-2026-40451/ #DeepL #XSS #CyberSecurity

    Post summary

    The post alerts users to an XSS flaw in the DeepL Chrome Extension (CVE‑2026‑40451) and urges them to update to mitigate the vulnerability.

    0000054
    7 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40451 DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in… https://www.cve.org/CVERecord?id=CVE-2026-40451 ----- Traducción: CVE-2026-40451 Las… http://infoflow.cloud`

    Post summary

    The tweet announces a cross‑site scripting vulnerability in certain versions of the DeepL Chrome extension and cites the CVE record.

    0000049
    72 followersView on X

Explore more