jsStringEscape of the component Incomplete Fix CVE-2026-23947. The manipulation leads to code injection.This vulnerability is listed as CVE-2026-25141. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.