By vendor
Appium vulnerabilities
Known CVEs affecting Appium products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-58191MEDIUM 6.5
Appium's base-driver component has a reflected cross-site scripting (XSS) vulnerability affecting versions prior to 10.7.0. The vulnerability exists in three built-in test routes that unconditionally mount without restriction. When users visit these endpoints, the application reflects unsanitized input from query parameters, POST fields, and HTTP headers directly into the HTML response. An attacker can craft a malicious link or form that executes arbitrary JavaScript in the victim's browser within the Appium server's origin, potentially compromising sessions or sensitive data accessible to that context.