CVE-2026-58191 is a medium-severity (CVSS 3.1 base 6.5) reflected cross-site scripting vulnerability in @appium/base-driver, the core driver package underlying the Appium mobile/browser automation server.
What the vulnerability does
Per the GitHub Security Advisory (GHSA-3wgp-x9p5-c7cc), Appium’s base driver mounts a set of built-in test routes (/test/guinea-pig and variants) unconditionally on every server, with no way to disable them. These routes reflect user-controlled input — a query parameter, a POST body field, and the User-Agent request header — directly into HTML via a template helper that performs no escaping. One of the reflected values lands inside a <script> block, meaning the flaw isn’t limited to markup injection: it allows arbitrary JavaScript execution in the context of the server’s own origin.
No authentication, session, driver, or plugin is required to reach these routes, and Appium’s default bind address is 0.0.0.0 — reachable from any network that can route to the server, not just localhost.
Fix and affected versions
Fixed in @appium/base-driver 10.7.0 (affecting 10.6.0 paired with Appium server 3.5.0, per the advisory). Update to 10.7.0 or later.
Why this matters
An attacker who gets a victim to open a crafted link (or trigger an auto-submitting form) targeting an Appium server can run arbitrary JavaScript in that server’s origin. Combined with Appium’s default open CORS policy and lack of authentication, that script can then drive the WebDriver REST API and any loaded plugin endpoints — turning a routine test-fixture route that should never be reachable on a production listener into a path toward controlling the automation session itself. Appium servers exposed beyond localhost, especially in CI/CD or device-farm environments, should prioritize this update.
Frequently Asked Questions
What is CVE-2026-58191?
A medium-severity (CVSS 6.5) reflected XSS vulnerability in Appium’s @appium/base-driver, where unconditionally-mounted test routes reflect unescaped user input, including inside a <script> block.
Which version fixes CVE-2026-58191?
@appium/base-driver 10.7.0 and later.
Is CVE-2026-58191 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the GitHub Advisory Database and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.