compileLodashTemplate of the file /test/guinea-pig of the component Route Handler. Such manipulation of the argument throwError/comments/User-Agent leads to cross site scripting.This vulnerability is documented as CVE-2026-58191. The attack can be executed remotely. There is not any exploit available.