Cross Site Scripting Vulnerability in Element Maps

Plan PatchCVSS 7.6SSA-682041Aug 27, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

The si-map component in Element maps-ng does not properly neutralize user-controllable input in the points property used to render tooltip labels on map pins. An attacker could craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This affects the @siemens/maps-ng package.

What this means
What could happen
An operator viewing a malicious map link in Element maps-ng could have their browser session compromised, allowing an attacker to steal credentials, modify plant data displays, or inject false operator commands.
Who's at risk
This affects operators using Siemens Element maps-ng (V47, V48, V49) for SCADA visualization, process monitoring dashboards, or geographic asset mapping. Any operator who opens externally-sourced map links or receives map URLs from external sources should be considered at risk.
How it could be exploited
An attacker crafts a malicious URL with JavaScript code injected into the points property of a map pin. When a victim loads the URL and hovers over the affected pin to view the tooltip, the malicious script executes in their browser with their current session privileges.
Prerequisites
  • Victim must click a malicious link crafted by attacker
  • Victim must hover over the affected map pin to trigger tooltip rendering
  • Browser must not have Content Security Policy restrictions enabled
remotely exploitablelow complexityrequires user interaction (clicking link and hovering)affects operator browser sessions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
Element maps-ng V48 < V48.11.3< 48.11.348.11.3
Element maps-ng V49 < V49.16.1< 49.16.149.16.1
Element maps-ng V47 < V47.12.3< 47.12.347.12.3
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDDeploy a strict Content Security Policy (CSP) to prevent inline script execution
HARDENINGEnable Trusted Types enforcement in your application to restrict dangerous DOM operations
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Element maps-ng to V47.12.3, V48.11.3, or V49.16.1 or later depending on your current version
HARDENINGMonitor access logs for suspicious map URLs or unusual script activity in Element maps-ng
API: /api/v1/advisories/5e445281-1354-4c7a-a79d-ce6b044bf41f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cross Site Scripting Vulnerability in Element Maps | CVSS 7.6 - OTPulse