PT-2026-64028 · Unknown · Fathom Lite

·

CVE-2026-65697

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fathom Lite versions prior to 1.3.2
Description A stored cross-site scripting issue exists in the analytics collection endpoint. Unauthenticated attackers can inject a javascript: URI into the Top Pages dashboard by sending a crafted hostname and pathname to the /collect endpoint. This occurs because the parseHostname() and parsePathname() functions do not perform URI scheme validation. Consequently, a javascript: hostname and a newline-prefixed pathname can be stored and subsequently rendered as an anchor href in the authenticated dashboard without sanitization. This can lead to session hijacking and full account takeover if an operator clicks the poisoned entry.
Recommendations Update Fathom Lite to version 1.3.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65697

Affected Products

Fathom Lite