Security Advisory

CVE-2026-55566

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-28 17:31:39
Last updated 2026-08-28 20:31:29
Assigner GitHub_M
CVSS score 4.3
State PUBLISHED

Description

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM rendering through innerHTML. A crafted URL can execute JavaScript when opened by a user. The script can read data available to the Yamcs web application and perform actions in the user context. This issue is fixed in versions 5.12.8 and 5.13.2.