CVE-2026-42458: Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
A reflected XSS vulnerability was found under admin panel -> System -> Import/Export -> Dataflow - Profiles.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42458 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →