# LEX Baza Dokumentów patches DOM XSS flaw

Published: 2026-04-30 · Severity: low
Canonical: https://vorant.io/reports/af5105a2-45d4-53c5-ad08-40031ec25374/lex-baza-dokument-w-patches-dom-xss-flaw

> A DOM-based XSS vulnerability in LEX Baza Dokumentów's cookie handling was patched in version 1.3.4, though CERT Polska rates the exploitation risk as minimal.

CERT Polska coordinated disclosure of CVE-2026-1493, a DOM-based cross-site scripting vulnerability in LEX Baza Dokumentów software. The flaw resides in the application's client-side processing of the "em" cookie parameter, which could allow an attacker to execute arbitrary JavaScript in a victim's browser context.

The vulnerability requires an attacker to have the ability to set cookies, significantly limiting the attack surface. CERT Polska assessed the impact and exploitation risk as minimal due to these constraints. Despite the low risk profile, the vendor acknowledged the issue as a security concern and released version 1.3.4 to address it.

The vulnerability was responsibly reported by Marek Figielski of Vanilla.pl and fixed through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1493

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-1493

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/af5105a2-45d4-53c5-ad08-40031ec25374/lex-baza-dokument-w-patches-dom-xss-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
