OsVault/npm/clevertap-web-sdk
npm

clevertap-web-sdk

2 known vulnerabilities · 0 critical · 0 high

CVE-2026-26862

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Published Feb 27, 2026
CVE-2026-26861

CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function

Published Feb 27, 2026
Check your entire dependency tree at onceRun dependency scan →