CVE-2026-35466: Cmu Cveclient

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Affected products

  • Cmu Cveclient: before 1.0.24 (fixed in 1.0.24)

Published 2026-04-02. Last modified 2026-07-24.