# DOM XSS Patched in LEX Baza Dokumentów

Published: 2026-04-30 · Severity: low
Canonical: https://vorant.io/reports/af5105a2-45d4-53c5-ad08-40031ec25374/dom-xss-patched-in-lex-baza-dokument-w

> A DOM-based XSS flaw in LEX Baza Dokumentów's cookie handling was patched in version 1.3.4 after coordinated disclosure via CERT Polska.

CERT Polska coordinated disclosure of CVE-2026-1493, a DOM-based cross-site scripting vulnerability in LEX Baza Dokumentów software. The flaw stems from unsafe client-side processing of the "em" cookie parameter, allowing an attacker capable of setting the cookie to execute arbitrary JavaScript within the victim's browser context.

CERT Polska notes that exploitation requires an attacker to already have the ability to set a cookie on the victim's browser, a precondition that would typically enable more severe attacks anyway. As a result, the practical risk and exploitation likelihood are assessed as minimal despite the vendor treating it as a legitimate vulnerability. The issue was responsibly reported by Marek Figielski of Vanilla.pl and has been fixed by the vendor in version 1.3.4.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1493

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-1493

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/af5105a2-45d4-53c5-ad08-40031ec25374/dom-xss-patched-in-lex-baza-dokument-w.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
