THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rxpg-wjf8-qv9c (medium) — Yamcs has Reflected XSS in the URL of the Authorize Endpoint

[GHSA] GHSA-rxpg-wjf8-qv9c (medium) — Yamcs has Reflected XSS in the URL of the Authorize Endpoint

medgithub_advisoriesPublished 2026-08-28

GHSA-rxpg-wjf8-qv9c Severity: medium CVE: CVE-2026-55549

Yamcs has Reflected XSS in the URL of the Authorize Endpoint

### Attack type:  Unauthenticated remote 

### Impact: Attackers can execute arbitrary JavaScript in a user's browser, including obtaining a user's session token and refresh token.

### Affected components: authorize.html, AuthHandler.java, HandlerContext.java

A Reflected Cros

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rxpg-wjf8-qv9c