Junglewise Threat Intelligence

CVE-2026-58500: Appium MCP Cross-Site Scripting in createLocatorGeneratorUI

CVE-2026-58500 · Severity: high · CVSS 8.2 · Published 2026-07-13

Vendors: npm.

Executive brief

Appium MCP is a tool that allows AI assistants to automate mobile app testing on Android and iOS. A security flaw allows a malicious mobile application to inject hidden code into the AI assistant's interface when a developer is testing that app. If successful, this could allow the attacker to trick the AI assistant into performing unauthorized actions, such as taking screenshots of the developer's screen or reading sensitive page data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the `createLocatorGeneratorUI` function of Appium MCP. The root cause is the direct interpolation of attacker-controlled element attributes (such as text, content-desc, and resource-id) into HTML template literals without proper escaping. An attacker who controls the UI of a mobile app under test can inject malicious JavaScript into the MCP UI resource. When a victim's MCP client renders this resource, the script can use `window.parent.postMessage` to invoke arbitrary MCP tools, leading to unauthorized actions like taking screenshots or reading page source. This issue is fixed in version 1.85.10.

Affected products

  • Appium appium-mcp < 1.85.10

Timeline

  • 2026-06-19: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Fix committed to repository

References

Related threats