THREAT OPS › Threat News › [GHSA] GHSA-9272-wg2r-7xmx (medium) — Yamcs has DOM XSS in Extension Routing
[GHSA] GHSA-9272-wg2r-7xmx (medium) — Yamcs has DOM XSS in Extension Routing
GHSA-9272-wg2r-7xmx Severity: medium CVE: CVE-2026-55566
Yamcs has DOM XSS in Extension Routing
**Attack type**: Unauthenticated remote **Impact**: Execution of arbitrary JavaScript in a user’s browser. **Affected components**: extension.matcher.ts:12, extension.component.ts:40, app.component.ts:134.
Yamcs is vulnerable to cross-site scripting in the /ext URL endpoint. By inputting specially c
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-55566cve
Original source: https://github.com/advisories/GHSA-9272-wg2r-7xmx