Medium severity6.1NVD Advisory· Published Mar 11, 2026· Updated May 7, 2026
CVE-2026-3884
CVE-2026-3884
Description
Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.snyk.io/vuln/SNYK-JS-SPINJS-15445079nvdThird Party Advisory
- gist.github.com/ericcornelissen/1a73e28fa50c3009b0eb51ad2fc19f25nvdBroken Link
News mentions
0No linked articles in our index yet.