---
id: CVE-2021-41184
title: jQuery-UI is the official jQuery user interface library
summary: >-
  jQuery-UI is the official jQuery user interface library. Prior to version
  1.13.0, accepting the value of the `of` option of the `.position()` util from
  untrusted sources may execute untrusted code. The issue is fixed in jQuery UI
  1.13.0.…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-79
  - CWE-79
vendor: jqueryui
product: jquery_ui
affected:
  - jquery_ui < 1.13.0
  - fedora = 33
  - fedora = 34
  - fedora = 35
  - fedora = 36
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h300e_firmware
  - h500e_firmware
  - h700e_firmware
  - h410s_firmware
  - h410c_firmware
  - 'drupal >= 7.0, < 7.86'
  - 'drupal >= 9.2.0, < 9.2.11'
  - 'drupal >= 9.3.0, < 9.3.3'
  - tenable.sc < 5.21.0
  - agile_product_lifecycle_management = 9.3.6
  - application_express < 22.1.1
  - banking_platform = 2.9.0
  - banking_platform = 2.12.0
  - big_data_spatial_and_graph < 23.1
  - big_data_spatial_and_graph = 23.1
  - communications_interactive_session_recorder = 6.4
  - communications_operations_monitor = 4.3
  - communications_operations_monitor = 4.4
  - communications_operations_monitor = 5.0
  - hospitality_inventory_management = 9.1.0
  - hospitality_materials_control = 18.1
  - 'hospitality_suite8 >= 8.11.0, <= 8.14.0'
  - hospitality_suite8 = 8.10.2
  - jd_edwards_enterpriseone_tools <= 9.2.6.3
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - 'policy_automation >= 12.2.0, <= 12.2.25'
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 18.8
  - primavera_unifier = 19.12
  - primavera_unifier = 20.12
  - primavera_unifier = 21.12
  - rest_data_services < 22.1.1
  - rest_data_services = 22.1.1
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
patched:
  - jquery_ui 1.13.0
  - drupal 9.3.3
  - tenable.sc 5.21.0
  - application_express 22.1.1
  - big_data_spatial_and_graph 23.1
  - rest_data_services 22.1.1
published: '2021-10-26'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41184'
references:
  - url: 'https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/'
    label: security-advisories@github.com
  - url: >-
      https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280
    label: security-advisories@github.com
  - url: >-
      https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html'
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20211118-0004/'
    label: security-advisories@github.com
  - url: 'https://www.drupal.org/sa-core-2022-001'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security-advisories@github.com
  - url: 'https://www.tenable.com/security/tns-2022-09'
    label: security-advisories@github.com
  - url: 'http://seclists.org/fulldisclosure/2024/Aug/37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211118-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.drupal.org/sa-core-2022-001'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2022-09'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.40768
epssPercentile: 0.98635
ingestedAt: '2026-08-25T17:29:31.743Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/gabrielolivra/Exploit-Medium-CVE-2021-41184'
  checkedAt: '2026-09-21T15:24:30.534Z'
exploitAvailable: true
---

## Overview

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

## Affected

- `jquery_ui < 1.13.0`
- `fedora = 33`
- `fedora = 34`
- `fedora = 35`
- `fedora = 36`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h300e_firmware`
- `h500e_firmware`
- `h700e_firmware`
- `h410s_firmware`
- `h410c_firmware`
- `drupal >= 7.0, < 7.86`
- `drupal >= 9.2.0, < 9.2.11`
- `drupal >= 9.3.0, < 9.3.3`
- `tenable.sc < 5.21.0`
- `agile_product_lifecycle_management = 9.3.6`
- `application_express < 22.1.1`
- `banking_platform = 2.9.0`
- `banking_platform = 2.12.0`
- `big_data_spatial_and_graph < 23.1`
- `big_data_spatial_and_graph = 23.1`
- `communications_interactive_session_recorder = 6.4`
- `communications_operations_monitor = 4.3`
- `communications_operations_monitor = 4.4`
- `communications_operations_monitor = 5.0`
- `hospitality_inventory_management = 9.1.0`
- `hospitality_materials_control = 18.1`
- `hospitality_suite8 >= 8.11.0, <= 8.14.0`
- `hospitality_suite8 = 8.10.2`
- `jd_edwards_enterpriseone_tools <= 9.2.6.3`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `policy_automation >= 12.2.0, <= 12.2.25`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 18.8`
- `primavera_unifier = 19.12`
- `primavera_unifier = 20.12`
- `primavera_unifier = 21.12`
- `rest_data_services < 22.1.1`
- `rest_data_services = 22.1.1`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`

## Remediation

Upgrade past the affected range:

- `jquery_ui 1.13.0`
- `drupal 9.3.3`
- `tenable.sc 5.21.0`
- `application_express 22.1.1`
- `big_data_spatial_and_graph 23.1`
- `rest_data_services 22.1.1`
