Disclosed on September 01, 2026 (updated September 01, 2026)
PGV-2664635 is a category 2 vulnerabilty that affects @appium/base-driver, versions < 10.7.0
The risk assessment shows that this vulnerability is exlpoited by a compromised user. A legitimate user who unknowingly triggers exploitation of this vulnerability through normal interaction.
The impact is contained to the application. Exploitation remains confined to the application and cannot affect the host environment or external systems.
The threat damage is caused by data tampering. Exploitation can result in modification of any data (authorized or not) within the system.
Appium's base-driver mounts the built-in /test/guinea-pig, /test/guinea-pig-scrollable and /test/guinea-pig-app-banner routes unconditionally on every server. The handler reflects the throwError query param, the comments POST field, and the User-Agent request header into the returned HTML via compileLodashTemplate, which interpolates <%= expr %> as String(expr) with no HTML/JS escaping. This yields reflected XSS, and the throwError value is reflected inside a <script> block, giving arbitrary JavaScript execution on the server's origin. No authentication, no session, no driver and no plugin are required, and the default bind address is 0.0.0.0.
@appium/base-driver 10.6.0 (with Appium server 3.5.0); tested live.@appium/base-driver lib/utils.ts compileLodashTemplate.base-driver/lib/express/server.ts:216-219app.all('/test/guinea-pig', guineaPig) etc.).base-driver/lib/express/static.ts:35-61 (guineaPigTemplate) —throwError = String(req.params.throwError ?? req.query?.throwError), params.comment = String(req.body.comments), params.userAgent = req.headers['user-agent'].base-driver/lib/utils.ts:67-83 (compileLodashTemplate)<%= expr %> as String(${expr}) via new Function(...), no escaping.base-driver/static/test/guinea-pig.html:11-12throwError inside <script>), :50 (comment), :87 (userAgent); same in guinea-pig-scrollable.html / guinea-pig-app-banner.html.Requests:
GET /test/guinea-pig?throwError=x%27%2balert(document.domain)%2b%27
POST /test/guinea-pig (body: comments=</span><img src=x onerror=alert(1)>)
GET /test/guinea-pig (header: User-Agent: <script>alert(7)</script>)
<img width="973" height="276" alt="image" src="https://github.com/user-attachments/assets/f58e1dce-f3ad-43d3-b66e-1ff5efea3866" />
An attacker who can get a victim to open a crafted link (or auto-submit a form) to the Appium server executes arbitrary JavaScript on the server's origin. With default CORS * + no authentication, that JS can drive the WebDriver REST API and plugin endpoints. The endpoints are debug/test fixtures that should not be reachable on a production listener at all.
| Network Exposure | External Accessable from the public internet |
| Access Interface | WebBrowser Primarily web-based applications |
| Service Outage | Disruptive Operations would be impacted |
| Data Breach | Disruptive Operations would be impacted |
| Data Tampering | Disruptive Operations would be impacted |
| Customize | |