Cross Site Scripting Vulnerability in Element Maps
Plan PatchCVSS 7.6SSA-682041Aug 27, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary
The si-map component in Element maps-ng does not properly neutralize user-controllable input in the points property used to render tooltip labels on map pins. An attacker could craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This affects the @siemens/maps-ng package.
What this means
What could happen
An operator viewing a malicious map link in Element maps-ng could have their browser session compromised, allowing an attacker to steal credentials, modify plant data displays, or inject false operator commands.
Who's at risk
This affects operators using Siemens Element maps-ng (V47, V48, V49) for SCADA visualization, process monitoring dashboards, or geographic asset mapping. Any operator who opens externally-sourced map links or receives map URLs from external sources should be considered at risk.
How it could be exploited
An attacker crafts a malicious URL with JavaScript code injected into the points property of a map pin. When a victim loads the URL and hovers over the affected pin to view the tooltip, the malicious script executes in their browser with their current session privileges.
Prerequisites
- Victim must click a malicious link crafted by attacker
- Victim must hover over the affected map pin to trigger tooltip rendering
- Browser must not have Content Security Policy restrictions enabled
remotely exploitablelow complexityrequires user interaction (clicking link and hovering)affects operator browser sessions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (3)
3 with fix
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDDeploy a strict Content Security Policy (CSP) to prevent inline script execution
HARDENINGEnable Trusted Types enforcement in your application to restrict dangerous DOM operations
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate Element maps-ng to V47.12.3, V48.11.3, or V49.16.1 or later depending on your current version
HARDENINGMonitor access logs for suspicious map URLs or unusual script activity in Element maps-ng
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5e445281-1354-4c7a-a79d-ce6b044bf41fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.