CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain

Subscriptions

Vendors Products
Clevertap Subscribe
Clevertap Web Sdk Subscribe
Web Sdk Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jfrq-hj9f-c8qx CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Clevertap clevertap Web Sdk
CPEs cpe:2.3:a:clevertap:clevertap_web_sdk:*:*:*:*:*:*:*:*
Vendors & Products Clevertap clevertap Web Sdk

Mon, 02 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Clevertap
Clevertap web Sdk
Vendors & Products Clevertap
Clevertap web Sdk

Fri, 27 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-829
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Description CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-27T19:39:16.900Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26862

cve-icon Vulnrichment

Updated: 2026-02-27T19:37:17.397Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T18:16:12.163

Modified: 2026-03-03T18:44:20.997

Link: CVE-2026-26862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-02T12:07:29Z

Weaknesses