Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2026-6019 - CVE Details, Severity, and Analysis | Strobes VI
inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","datePublished":"2026-05-01T00:35:40.469000","dateModified":"2026-05-01T01:56:24.643000","author":{"@type":"Organization","name":"Strobes Security","url":"https://strobes.co"},"publisher":{"@type":"Organization","name":"Strobes VI","url":"https://vi.strobes.co"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://vi.strobes.co/cve/CVE-2026-6019"},"about":{"@type":"Thing","name":"CVE-2026-6019","description":"Security vulnerability CVE-2026-6019 with CVSS score 0"},"keywords":["CVE-2026-6019","CVE","vulnerability","security","low","patch available"]} inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}},{"@type":"Question","name":"What is the severity of CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-6019 has a CVSS v3 score of 0, which is classified as Low severity."}},{"@type":"Question","name":"Is there an exploit available for CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"No known public exploits are currently available for CVE-2026-6019."}},{"@type":"Question","name":"Is there a patch available for CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"Yes, patches are available for CVE-2026-6019. Check the vendor advisories for update instructions."}}]}
CVE-2026-6019
Published: May 1, 2026
Last updated:
Exploit: NoZero-day: NoPatch: Yes
TL;DR
CVE-2026-6019 is a low severity vulnerability with a CVSS score of 0.0. No known exploits currently, and patches are available.
Key Points
1Low severity (CVSS 0.0/10)
2No known public exploits
3
Severity Scores
CVSS v30.0
CVSS v20.0
Priority Score0.0
EPSS Score0.0
None
Cite This Page
APA Format
Strobes VI. (2026). CVE-2026-6019 - CVE Details and Analysis. Strobes VI. Retrieved May 4, 2026, from https://vi.strobes.co/cve/CVE-2026-6019
Quick copy link + title
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
Description
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.