PT-2026-56249 · Dashy · Dashy

·

CVE-2026-55592

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dashy versions prior to 4.3.7
Description The workspace view fails to validate the scheme of the URL query parameter before assigning it to an iframe source. This allows an attacker to execute JavaScript on the Dashy origin by tricking a logged-in user into opening a crafted workspace link containing a javascript: URL. This execution enables the attacker to read same-origin browser data, interact with the Document Object Model (DOM), and send requests on behalf of the victim.
Recommendations Update to version 4.3.7.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55592
GHSA-58MP-4QR3-VMRC

Affected Products

Dashy