CVE-2026-21768
MEDIUMCVSS v3.1: 6.3
Source data as of:
At a glance
- Severity
- MEDIUM
- CVSS
- 6.3 v3.1 · NVD
- EPSS
- EPSS not provided by FIRST.org for this CVE
- CISA KEV
- No
- Type
- Improper Input Validation, XSS · NVD CWE
- Attack conditions (CVSS vector)
- No privileges · Source: NVD Vector
- Published
- 2026-06-19 · Modified: 2026-06-19
- References
- Jump to references (1)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.