Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
← Back to the register

maplibre-gl

CriticalnpmCVE-2026-85061

What to do

Update maplibre-gl to 6.4.1 or later.

npm install maplibre-gl@6.4.1

A cross-site scripting flaw affects the npm package maplibre-gl. Affected versions: <= 6.4.0. Fixed from version 6.4.1. CVSS score 10.

What the flaw allows: Code can run in visitors’ browsers.

Package
maplibre-gl
Ecosystem
npm (JavaScript)
Class
Cross-site scripting
Affected versions
<= 6.4.0
CVSS
10
Published on
September 8, 2026

Sources

Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.