CVE-2026-85630

MEDIUM CVSS 3.1: 6.1 EPSS 0.24%
Updated Sep 10, 2026
HTML
Parameter Value
CVSS 6.1 (MEDIUM)
Affected Versions before 0.410002
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor HTML
Public PoC No

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages. For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1