The Appium Java Client vulnerability (CVE-2026-43910) exists in versions from 8.2.1 until 10.1.1, where directConnect(true) is enabled. This allows a rogue or compromised server to redirect session traffic to an arbitrary destination, enabling full interception and server-side request forgery. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The vu [truncated]
MCP Appium versions prior to 1.85.10 are vulnerable to AI tool execution via injected HTML and JavaScript. The createLocatorGeneratorUI function interpolates attacker-controlled element attributes into an HTML template literal without escaping, allowing an attacker to inject arbitrary HTML and JavaScript. When a victim's MCP client renders this resource, the injected script executes and can invoke arbitra [truncated]
The Appium storage plugin has a vulnerability prior to version 1.1.6. An unauthenticated remote client can exploit the POST /storage/delete endpoint to escape the storage root and recursively delete arbitrary writable files or directories using ../ sequences. This issue is fixed in version 1.1.6. The vulnerability allows for potential unauthorized file or directory deletion, impacting users of Appium vers [truncated]
CVE-2026-58191 is a reflected cross-site scripting vulnerability in Appium, a cross-platform automation framework. The issue allows for arbitrary JavaScript execution on the server origin due to improper escaping of user input in certain routes, including /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner. This vulnerability has a CVSS score of 6.5 and is considered Medium seve [truncated]