THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c7hr-448w-65px (high) — MeshCentral has unsanitized data fields

[GHSA] GHSA-c7hr-448w-65px (high) — MeshCentral has unsanitized data fields

highgithub_advisoriesPublished 2026-08-18

GHSA-c7hr-448w-65px Severity: high CVE: None

MeshCentral has unsanitized data fields

### Description

A rogue or compromised MeshAgent can inject arbitrary HTML/JavaScript via the osdesc (OS description) field in its coreinfo message. The server stores this value with zero HTML sanitization (meshagent.js:1903 only checks typeof == 'string'). When an admin views the device details panel, the valu

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c7hr-448w-65px