Stored Cross-Site Scripting in Malla Web Analyzer for Meshtastic Networks
CVE-2026-43980
6.3MEDIUM
What is CVE-2026-43980?
Malla, a web analyzer for Meshtastic networks, previously allowed code names to be submitted via MQTT without proper sanitization. This oversight enabled attackers to inject malicious JavaScript into the dashboard, potentially compromising the security of any user accessing the platform. The issue has been addressed in a recent commit that ensures appropriate sanitization and escaping of user inputs before rendering in the DOM.
Affected Version(s)
malla < 4086e2b5f61615a813b70b25bc76095083552135
