{"id":"CVE-2026-49864","aliases":["GHSA-p26j-h7wj-r568"],"url":"https://o3.security/vulnerability/CVE-2026-49864","summary":"wetty vulnerable to DOM XSS via file-download filename","details":"wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\\x1b[5i...:...\\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session. Version 3.0.4 fixes the issue.","published":"2026-08-13T19:10:41.037Z","modified":"2026-08-14T04:03:54.682466756Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"wetty","fixedVersion":"3.0.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49864.json"},{"type":"ADVISORY","url":"https://github.com/butlerx/wetty/security/advisories/GHSA-p26j-h7wj-r568"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49864"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T04:03:54.682466756Z"}}