fullmatch. Performing a manipulation results in permissive cross-domain policy with untrusted domains.This vulnerability is reported as CVE-2026-25478. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.