Package
opensearch-dashboards-3-dashboards-maps
Component
maplibre-gl
Latest update
10.0
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-85061 (GHSA-jrc7-96c5-q579, Critical) is an XSS sanitizer bypass in maplibre-gl's DOM.sanitize(); fixed in maplibre-gl 6.4.1 (https://github.com/maplibre/maplibre-gl-js/releases/tag/v6.4.1), the only patched release. The OpenSearch Dashboards maps plugin (dashboards-maps, https://github.com/opensearch-project/dashboards-maps) at 3.8.0.0 pins maplibre-gl 5.2.0 (this package holds it at 5.23.0) and imports the CSP build entry point maplibre-gl/dist/maplibre-gl-csp in public/plugin.tsx and public/components/map_container/map_container.tsx; maplibre-gl 6.x removed that entry point and is an ESM-only, WebGL2-only distribution with Map/event/GeoJSON API changes, so the plugin does not build against 6.4.1 without plugin code changes. Upstream's main branch is still on maplibre-gl 5.2.0; the upstream bump to 6.4.1 is open at https://github.com/opensearch-project/dashboards-maps/pull/865, fails upstream CI, and has not been released. The scanner reports the same maplibre-gl copy twice (node_modules/maplibre-gl and the node_modules/mapbox-gl alias directory). Remediation depends on upstream dashboards-maps adopting maplibre-gl 6.4.1 or later. Waiting for the first upstream release containing the fix. References: https://github.com/maplibre/maplibre-gl-js/security/advisories/GHSA-jrc7-96c5-q579
Status