StackRadar

CVE-2026-46625

High

Advisory

Published 21 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 1
affected package

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
js-cookienpm2.2.1, 3.0.1, 3.0.53.0.756
OSV records
GHSA-qjx8-664m-686j

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
js-cookie@3.0.5
3.0.7

Open the chart page →

2,133
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
js-cookie@2.2.1
3.0.7

Open the chart page →

2,460
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
js-cookie@3.0.5
3.0.7

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
js-cookie@3.0.5
3.0.7

Open the chart page →

5,604
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
js-cookie@3.0.5
3.0.7

Open the chart page →

5,228
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
js-cookie@3.0.5
3.0.7

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
js-cookie@2.2.1
3.0.7

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
js-cookie@2.2.1
3.0.7

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
js-cookie@2.2.1
3.0.7

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
js-cookie@2.2.1
3.0.7

Open the chart page →

9,381

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sct/overseerr:1.26.1254d16af8f71
js-cookie@2.2.1
3.0.7
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
js-cookie@3.0.5
3.0.7
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
js-cookie@3.0.5
3.0.7
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
js-cookie@3.0.5
3.0.7
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
js-cookie@2.2.1
3.0.7
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
js-cookie@3.0.5
3.0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.