CVE-2026-39379: GeoNetwork has reflected XSS through client-side template injection
(updated )
It is possible to craft a URL that causes GeoNetwork to reflect attacker-controlled content into an error page in a way that gets evaluated as a client-side template expression. Combined with known AngularJS sandbox-escape techniques, this can be used to execute arbitrary JavaScript in the victim’s browser (reflected Cross-Site Scripting via client-side template injection).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-39379 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →