Cross-site scripting in TerriaJS-Server - CVE-2026-77636
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper content-type handling in the gist-backed share resolver when a browser directly navigates to a raw share endpoint. A remote attacker can host crafted markup in a public gist and distribute its share URL to execute arbitrary script in a victim's browser.
User interaction is required to open the crafted URL, and only deployments configured with a gist-backed share URL prefix are affected.