PT-2026-55212 · Butlerx+2 · Wetty
CVE-2026-49864
·
Published
2026-07-01
·
Updated
2026-08-18
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
wetty versions prior to 3.0.4
Description
The wetty client improperly handles file-download escape sequences by decoding a base64 filename and interpolating it directly into a Toastify HTML string without escaping. An attacker can deliver a specially crafted escape sequence (
x1b[5i...:...x1b[4i) through any output the victim renders in the terminal, such as a file read via cat, a tailed log, an SSH MOTD, or a curl response. This allows the execution of arbitrary JavaScript within the wetty origin, which can be used to read terminal contents or inject attacker-chosen keystrokes into the victim's active SSH session via the window.wetty term.input() function.Recommendations
Update to version 3.0.4.
As a temporary mitigation, avoid rendering untrusted files or output in the terminal while using wetty.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wetty