| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9272-wg2r-7xmx | Yamcs has DOM XSS in Extension Routing |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yamcs
Yamcs yamcs |
|
| Vendors & Products |
Yamcs
Yamcs yamcs |
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM rendering through innerHTML. A crafted URL can execute JavaScript when opened by a user. The script can read data available to the Yamcs web application and perform actions in the user context. This issue is fixed in versions 5.12.8 and 5.13.2. | |
| Title | Yamcs: DOM XSS in Extension Routing | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-28T20:31:29.178Z
Reserved: 2026-06-16T23:11:20.214Z
Link: CVE-2026-55566
Updated: 2026-08-28T20:30:47.765Z
Status : Received
Published: 2026-08-28T20:18:29.207
Modified: 2026-08-28T22:16:51.187
Link: CVE-2026-55566
No data.
OpenCVE Enrichment
Updated: 2026-08-28T21:45:03Z
Github GHSA