CVE-2026-32289 is a template injection vulnerability affecting JavaScript template literals where context tracking across branch conditions fails, resulting in improper escaping of dynamic content and brace depth miscalculation. This flaw enables attackers to bypass intended security controls and inject malicious scripts, leading to cross-site scripting (XSS) vulnerabilities in affected applications. The vulnerability carries a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring minimal complexity and no elevated privileges, though user interaction is necessary. The attack has limited scope with low confidentiality and integrity impact, posing moderate risk to affected systems. There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat monitoring lists. The extremely low EPSS score of 0.0001 indicates minimal probability of near-term exploitation, suggesting this vulnerability currently poses a lower practical threat despite its technical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.9CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.2CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.