CVE-2021-41182 is a cross-site scripting vulnerability in the jQuery UI Datepicker widget before version 1.13.0. An untrusted value supplied to the Datepicker altField option can be interpreted in a manner that permits execution of attacker-controlled script in the context of the application. Version 1.13.0 changes handling of string altField values so they are treated as CSS selectors.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
altField option can execute arbitrary JavaScript in a victim's browser under the affected application's origin. This can enable theft or misuse of session-bound data, modification of application content, and actions performed with the victim's privileges.If you can’t patch tonight, do this now.
altField option from untrusted input. Restrict this option to developer-controlled, validated CSS selectors until the dependency can be upgraded.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (POC) exploit for CVE-2021-41182, a cross-site scripting (XSS) vulnerability in jQuery UI versions prior to 1.13.0. The vulnerability exists in the Datepicker widget's 'altField' option, which does not properly sanitize untrusted input, allowing attackers to inject and execute arbitrary JavaScript in the victim's browser. The main exploit is implemented as a Nuclei YAML template (CVE-2021-41182.yaml), which automates the process of testing for the vulnerability by navigating to a target URL, injecting a malicious payload into the altField, and checking for JavaScript execution via alert dialogs. The repository also includes HTML files and both vulnerable (1.12.1) and patched (1.13.3) versions of jQuery UI for local testing. The exploit demonstrates the impact of the vulnerability and can be used to verify whether a web application is affected. No weaponized or automated exploitation is present; the code is focused on detection and demonstration of the XSS issue.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-site scripting vulnerability in the altField option of the jQuery UI datepicker widget.
A vulnerability in the jQuery dependency (as used by Adobe Commerce) that could allow arbitrary code execution, addressed via dependency update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.