THREAT OPS › Threat News › [GHSA] GHSA-rxpg-wjf8-qv9c (medium) — Yamcs has Reflected XSS in the URL of the Authorize Endpoint
[GHSA] GHSA-rxpg-wjf8-qv9c (medium) — Yamcs has Reflected XSS in the URL of the Authorize Endpoint
GHSA-rxpg-wjf8-qv9c Severity: medium CVE: CVE-2026-55549
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
### Attack type: Unauthenticated remote
### Impact: Attackers can execute arbitrary JavaScript in a user's browser, including obtaining a user's session token and refresh token.
### Affected components: authorize.html, AuthHandler.java, HandlerContext.java
A Reflected Cros
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-55549cve
Original source: https://github.com/advisories/GHSA-rxpg-wjf8-qv9c