StackRadar

CVE-2026-46625

High

Advisory

Published 21 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 1
affected package

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
js-cookienpm2.2.1, 3.0.1, 3.0.53.0.756
OSV records
GHSA-qjx8-664m-686j

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
js-cookie@3.0.5
3.0.7

Open the chart page →

2,133
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
js-cookie@2.2.1
3.0.7

Open the chart page →

2,460
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
js-cookie@3.0.5
3.0.7

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
js-cookie@3.0.5
3.0.7

Open the chart page →

5,604
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
js-cookie@3.0.5
3.0.7

Open the chart page →

5,228
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
js-cookie@3.0.5
3.0.7

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
js-cookie@2.2.1
3.0.7

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
js-cookie@2.2.1
3.0.7

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
js-cookie@2.2.1
3.0.7

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-46625.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
js-cookie@2.2.1
3.0.7

Open the chart page →

9,381

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rcdelacruz/my-strapi-app:js-amd6438007f358355
js-cookie@2.2.1
3.0.7
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
js-cookie@2.2.1
3.0.7
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
js-cookie@2.2.1
3.0.7
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
js-cookie@2.2.1
3.0.7
2
rajnandan1/kener:3.2.1930407afca731
js-cookie@3.0.5
3.0.7
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
js-cookie@3.0.5
3.0.7
2
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
js-cookie@2.2.1
3.0.7
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
js-cookie@2.2.1
3.0.7
1
baserow/baserow:1.30.1df0c42eb67e8
js-cookie@3.0.5
3.0.7
1
codetogether/codetogether:latest4348c8a38752
js-cookie@2.2.1
3.0.7
1
conduction/conduction-ui-app:devd591f5e6f2a9
js-cookie@2.2.1
3.0.7
1
etherpad/etherpad:2.7.2b723fe5f2594
js-cookie@3.0.5
3.0.7
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
js-cookie@2.2.1
3.0.7
1
henrywhitaker3/speedtest-tracker:latest47159a940229
js-cookie@2.2.1
3.0.7
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
js-cookie@3.0.1
3.0.7
1
lavandadelpatio/frontend:latest501c3f31e0bc
js-cookie@2.2.1
3.0.7
1
library/ghost:6.37.01ef2e532ca4d
js-cookie@3.0.5
3.0.7
1
library/ghost:6.41.129773d6be407
js-cookie@3.0.5
3.0.7
1
library/ghost:6.39.0-alpine77196da4b0df
js-cookie@3.0.5
3.0.7
1
library/kibana:7.17.150172f1c538e7
js-cookie@2.2.1
3.0.7
1
library/kibana:8.18.004c0fc150f3a
js-cookie@2.2.1
3.0.7
1
library/kibana:7.17.8c5781ba340ef
js-cookie@2.2.1
3.0.7
1
library/kibana:7.17.3e2e2031c15be
js-cookie@2.2.1
3.0.7
1
linuxserver/codimd:latestb801bbcf6386
js-cookie@2.2.1
3.0.7
1
mautic/mautic:7-apacheeb8cc73d97e1
js-cookie@2.2.1
3.0.7
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
js-cookie@2.2.1
3.0.7
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
js-cookie@2.2.1
3.0.7
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
js-cookie@2.2.1
3.0.7
1
phntom/codimd:2.4.31b9aafbb62e6
js-cookie@2.2.1
3.0.7
1
redis/redisinsight:2.68019fcf774631
js-cookie@3.0.5
3.0.7
1
redis/redisinsight:3.2.055542a762210
js-cookie@3.0.5
3.0.7
1
redis/redisinsight:2.46699d341bd329
js-cookie@3.0.5
3.0.7
1
redis/redisinsight:3.485562d67a912
js-cookie@3.0.5
3.0.7
1
roadiehq/community-backstage-image:latestef355bf5b639
js-cookie@2.2.1
3.0.7
1
sigp/siren:v3.0.42c219b04758e
js-cookie@3.0.5
3.0.7
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
js-cookie@3.0.5
3.0.7
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
js-cookie@2.2.1
3.0.7
1
wazuh/wazuh-dashboard:4.4.11787550d2358
js-cookie@2.2.1
3.0.7
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
js-cookie@2.2.1
3.0.7
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
js-cookie@2.2.1
3.0.7
1
ghcr.io/caninehq/canine:latesta058034ca006
js-cookie@3.0.5
3.0.7
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
js-cookie@3.0.5
3.0.7
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
js-cookie@3.0.5
3.0.7
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
js-cookie@3.0.5
3.0.7
1
ghcr.io/data-fair/metrics:0a8d40779eeae
js-cookie@3.0.1
3.0.7
1
ghcr.io/data-fair/notify:3c739b74dabb0
js-cookie@3.0.5
3.0.7
1
ghcr.io/data-fair/processings:15a9216989707
js-cookie@3.0.5
3.0.7
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
js-cookie@3.0.1
3.0.7
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
js-cookie@3.0.5
3.0.7
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
js-cookie@3.0.5
3.0.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.