PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Sep 14, 2026

Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-58191
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError query parameter, comments POST field, and User-Agent request header into HTML without escaping, allowing reflected cross-site scripting and arbitrary JavaScript execution on the server origin. This issue is fixed in version 10.7.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
appiumby appium
< 10.7.0
Updated Sep 14, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting CVE-2026-58191 Scanner | S4E