PT-2026-55212 · Butlerx+2 · Wetty

CVE-2026-49864

·

Published

2026-07-01

·

Updated

2026-08-18

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wetty versions prior to 3.0.4
Description The wetty client improperly handles file-download escape sequences by decoding a base64 filename and interpolating it directly into a Toastify HTML string without escaping. An attacker can deliver a specially crafted escape sequence (x1b[5i...:...x1b[4i) through any output the victim renders in the terminal, such as a file read via cat, a tailed log, an SSH MOTD, or a curl response. This allows the execution of arbitrary JavaScript within the wetty origin, which can be used to read terminal contents or inject attacker-chosen keystrokes into the victim's active SSH session via the window.wetty term.input() function.
Recommendations Update to version 3.0.4. As a temporary mitigation, avoid rendering untrusted files or output in the terminal while using wetty.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49864
GHSA-P26J-H7WJ-R568

Affected Products

Wetty