{"id":"CVE-2026-79320","title":"Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime","summary":"Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the te…","severity":"none","published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:56:19.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79320","references":[{"url":"https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79320.md","label":"cve@mitre.org"},{"url":"https://github.com/stenciljs/core","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00142,"epssPercentile":0.03912,"ingestedAt":"2026-09-21T19:51:58.869Z","slug":"CVE-2026-79320","body":"## Overview\n\nStencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the textContent property of such a component's host element causes the value to be parsed as HTML instead of being inserted as text. If an application writes attacker-controlled data to these host elements, the data can be interpreted as markup and script can execute in the context of the application's origin.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}