Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities. | |
| Title | JsBraceDepth Context Tracking Bugs (XSS) in html/template | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-04-08T01:06:56.297Z
Reserved: 2026-03-11T16:38:46.557Z
Link: CVE-2026-32289
No data.
Status : Received
Published: 2026-04-08T02:16:03.820
Modified: 2026-04-08T02:16:03.820
Link: CVE-2026-32289
No data.
OpenCVE Enrichment
No data.