漏洞概述 漏洞名称: Prototype pollution leading to stored XSS (CVE-2026-23929) 漏洞类型: 缺陷 (Security) 严重程度: 8.5 (High) CVSS向量: CVSS:3.0/AV:N/AC:L/AT:N/PR:L/UI:R/S:C/C:H/I:H/A:N/S:C/N/S:A/N 描述: Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like _proto_, combined with jQuery's unsafe element creation that traversed the prototype chain. 影响范围 受影响组件: Frontend 受影响和修复版本: - Affected: 6.0.44 - 6.0.45 – Fixed: 6.0.46 - Affected: 7.0.22 - 7.0.24 – Fixed: 7.0.25 - Affected: 7.4.6 - 7.4.8 – Fixed: 7.4.9 修复方案 修复状态: Fixed 修复版本: 见上述受影响和修复版本 缓解措施: Update the affected components to their respective fixed versions. 变通方法: Update the affected components to their respective fixed versions. 其他信息 CVE ID: CVE-2026-23929 CVSS Score: 8.5 (High) CVSS Vector: CVSS:3.0/AV:N/AC:L/AT:N/PR:L/UI:R/S:C/C:H/I:H/A:N/S:C/N/S:A/N 已知攻击向量: An authenticated Zabbix user could inject the malicious HTML into the Zabbix UI (Map page). 致谢: Zabbix wants to thank Perce, 6o_09 and Nassim BETTACH @Shenron for submitting this report on the HackerOne bug bounty platform.