Skip to main content
QUIETLYTIC
Vulnerability

@appium/base-driver Cross-Site Scripting (CVE-2026-58191)

CVE-2026-58191 lets an attacker execute arbitrary JavaScript on an Appium server via unauthenticated, unescaped test routes mounted on every server by default.

CVE-2026-58191
Threat Level
MEDIUM
CVSS
6.5
Status
Monitored
Confidence
High
Affected Products
npm:@appium/base-driver

CVE-2026-58191 is a medium-severity (CVSS 3.1 base 6.5) reflected cross-site scripting vulnerability in @appium/base-driver, the core driver package underlying the Appium mobile/browser automation server.

What the vulnerability does

Per the GitHub Security Advisory (GHSA-3wgp-x9p5-c7cc), Appium’s base driver mounts a set of built-in test routes (/test/guinea-pig and variants) unconditionally on every server, with no way to disable them. These routes reflect user-controlled input — a query parameter, a POST body field, and the User-Agent request header — directly into HTML via a template helper that performs no escaping. One of the reflected values lands inside a <script> block, meaning the flaw isn’t limited to markup injection: it allows arbitrary JavaScript execution in the context of the server’s own origin.

No authentication, session, driver, or plugin is required to reach these routes, and Appium’s default bind address is 0.0.0.0 — reachable from any network that can route to the server, not just localhost.

Fix and affected versions

Fixed in @appium/base-driver 10.7.0 (affecting 10.6.0 paired with Appium server 3.5.0, per the advisory). Update to 10.7.0 or later.

Why this matters

An attacker who gets a victim to open a crafted link (or trigger an auto-submitting form) targeting an Appium server can run arbitrary JavaScript in that server’s origin. Combined with Appium’s default open CORS policy and lack of authentication, that script can then drive the WebDriver REST API and any loaded plugin endpoints — turning a routine test-fixture route that should never be reachable on a production listener into a path toward controlling the automation session itself. Appium servers exposed beyond localhost, especially in CI/CD or device-farm environments, should prioritize this update.

Frequently Asked Questions

What is CVE-2026-58191? A medium-severity (CVSS 6.5) reflected XSS vulnerability in Appium’s @appium/base-driver, where unconditionally-mounted test routes reflect unescaped user input, including inside a <script> block.

Which version fixes CVE-2026-58191? @appium/base-driver 10.7.0 and later.

Is CVE-2026-58191 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the GitHub Advisory Database and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 GitHub Advisory Database
02 National Vulnerability Database (NVD)

Related intelligence


Analyst tools