CVE-2026-21768

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-19 15:16

Updated : 2026-06-22 20:42


NVD link : CVE-2026-21768

Mitre link : CVE-2026-21768

CVE.ORG link : CVE-2026-21768


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')