Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2026-6019 - CVE Details, Severity, and Analysis | Strobes VI
inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","datePublished":"2026-05-23T08:42:25.477000","dateModified":"2026-05-23T10:02:18.452000","author":{"@type":"Organization","name":"Strobes Security","url":"https://strobes.co"},"publisher":{"@type":"Organization","name":"Strobes VI","url":"https://vi.strobes.co"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://vi.strobes.co/cve/CVE-2026-6019"},"about":{"@type":"Thing","name":"CVE-2026-6019","description":"Security vulnerability CVE-2026-6019 with CVSS score 6.1"},"keywords":["CVE-2026-6019","CVE","vulnerability","security","medium","exploit available","patch available","Cpython"]} inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}},{"@type":"Question","name":"What is the severity of CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-6019 has a CVSS v3 score of 6.1, which is classified as Medium severity."}},{"@type":"Question","name":"Is there an exploit available for CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"Yes, there are known exploits available for CVE-2026-6019. Immediate patching is recommended."}},{"@type":"Question","name":"Is there a patch available for CVE-2026-6019?","acceptedAnswer":{"@type":"Answer","text":"Yes, patches are available for CVE-2026-6019. Check the vendor advisories for update instructions."}}]}
CVE-2026-6019
Published: May 23, 2026
Last updated:
Exploit: YesZero-day: NoPatch: Yes
TL;DR
CVE-2026-6019 is a medium severity vulnerability with a CVSS score of 6.1. Exploits are available; patches have been released and should be applied urgently.
Key Points
1Medium severity (CVSS 6.1/10)
2Public exploits are available
3
Severity Scores
CVSS v36.1
CVSS v20.0
Priority Score266.0
EPSS Score0.0
Medium
Cite This Page
APA Format
Strobes VI. (2026). CVE-2026-6019 - CVE Details and Analysis. Strobes VI. Retrieved May 25, 2026, from https://vi.strobes.co/cve/CVE-2026-6019
Quick copy link + title
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
Description
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
NVD: http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.