Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p26j-h7wj-r568 | wetty vulnerable to DOM XSS via file-download filename |
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Butlerx
Butlerx wetty |
|
| Vendors & Products |
Butlerx
Butlerx wetty |
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\x1b[5i...:...\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session. Version 3.0.4 fixes the issue. | |
| Title | wetty vulnerable to DOM XSS via file-download filename | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T19:10:41.037Z
Reserved: 2026-06-01T22:03:19.640Z
Link: CVE-2026-49864
No data.
Status : Received
Published: 2026-08-13T20:17:22.720
Modified: 2026-08-13T20:17:22.720
Link: CVE-2026-49864
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:30:53Z
Github GHSA