CVE-2026-3884 | spin.js up to 2.x URL target cross site scripting (SNYK-JS-SPINJS-15445079 / Nessus ID 302200)
A vulnerability was found in spin.js up to 2.x and classified as problematic. This impacts an unknown function of the component URL Handler. Executing a manipulation of the argument target can lead to cross site scripting.
This vulnerability is handled as CVE-2026-3884. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.