Stored Cross-Site Scripting in Malla Web Analyzer for Meshtastic Networks
CVE-2026-43980

6.3MEDIUM

Key Information:

Vendor

Zenitram

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-43980?

Malla, a web analyzer for Meshtastic networks, previously allowed code names to be submitted via MQTT without proper sanitization. This oversight enabled attackers to inject malicious JavaScript into the dashboard, potentially compromising the security of any user accessing the platform. The issue has been addressed in a recent commit that ensures appropriate sanitization and escaping of user inputs before rendering in the DOM.

Affected Version(s)

malla < 4086e2b5f61615a813b70b25bc76095083552135

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.