Internet Explorer is no longer supported. Many things will still work, but your experience will be degraded and some things won't function. Please use a modern browser such as Edge, Chrome, or Firefox.

PGV-2664635 - Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Disclosed on September 01, 2026 (updated September 01, 2026)

Vulnerability Overview

PGV-2664635 is a category 2 vulnerabilty that affects @appium/base-driver, versions < 10.7.0

Risk Assessment

The risk assessment shows that this vulnerability is exlpoited by a compromised user. A legitimate user who unknowingly triggers exploitation of this vulnerability through normal interaction.

The impact is contained to the application. Exploitation remains confined to the application and cannot affect the host environment or external systems.

The threat damage is caused by data tampering. Exploitation can result in modification of any data (authorized or not) within the system.

Vulnerability Details

Summary

Appium's base-driver mounts the built-in /test/guinea-pig, /test/guinea-pig-scrollable and /test/guinea-pig-app-banner routes unconditionally on every server. The handler reflects the throwError query param, the comments POST field, and the User-Agent request header into the returned HTML via compileLodashTemplate, which interpolates <%= expr %> as String(expr) with no HTML/JS escaping. This yields reflected XSS, and the throwError value is reflected inside a <script> block, giving arbitrary JavaScript execution on the server's origin. No authentication, no session, no driver and no plugin are required, and the default bind address is 0.0.0.0.

Details

Affected

  • @appium/base-driver 10.6.0 (with Appium server 3.5.0); tested live.
  • Template engine helper: @appium/base-driver lib/utils.ts compileLodashTemplate.

Location (file:line)

  • Routes mounted unconditionally: base-driver/lib/express/server.ts:216-219
    (app.all('/test/guinea-pig', guineaPig) etc.).
  • Tainting: base-driver/lib/express/static.ts:35-61 (guineaPigTemplate) —
    throwError = String(req.params.throwError ?? req.query?.throwError), params.comment = String(req.body.comments), params.userAgent = req.headers['user-agent'].
  • Unescaped render: base-driver/lib/utils.ts:67-83 (compileLodashTemplate)
    emits <%= expr %> as String(${expr}) via new Function(...), no escaping.
  • Sinks (shipped templates): base-driver/static/test/guinea-pig.html:11-12
    (throwError inside <script>), :50 (comment), :87 (userAgent); same in guinea-pig-scrollable.html / guinea-pig-app-banner.html.

PoC

Requests:

GET /test/guinea-pig?throwError=x%27%2balert(document.domain)%2b%27
POST /test/guinea-pig         (body: comments=</span><img src=x onerror=alert(1)>)
GET  /test/guinea-pig         (header: User-Agent: <script>alert(7)</script>)

<img width="973" height="276" alt="image" src="https://github.com/user-attachments/assets/f58e1dce-f3ad-43d3-b66e-1ff5efea3866" />

Impact

An attacker who can get a victim to open a crafted link (or auto-submit a form) to the Appium server executes arbitrary JavaScript on the server's origin. With default CORS * + no authentication, that JS can drive the WebDriver REST API and plugin endpoints. The endpoints are debug/test fixtures that should not be reachable on a production listener at all.

Common Weakness Enumerations

  • CWE-489 - Active Debug Code
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Your Risk Profile
Network Exposure
External
Accessable from the public internet
Access Interface
WebBrowser
Primarily web-based applications
Service Outage
Disruptive
Operations would be impacted
Data Breach
Disruptive
Operations would be impacted
Data Tampering
Disruptive
Operations would be impacted
Customize
Additional Identifiers
  • CVE-2026-58191
  • GHSA-3wgp-x9p5-c7cc