Cross-Site Scripting Vulnerability in Yamcs Mission Control Framework
CVE-2026-55566
4.3MEDIUM
What is CVE-2026-55566?
Prior to specific updates, Yamcs, a mission control framework, processed unverified data from attacker-controlled URLs without proper validation of registered plugin IDs. This oversight allowed for the potential execution of JavaScript within the context of the application. When a crafted URL was accessed, the embedded script could read sensitive information and interact with the web application as the authenticated user. The issue was mitigated in versions 5.12.8 and 5.13.2, which implemented necessary security checks to prevent such attacks.
Affected Version(s)
yamcs < 5.12.8 < 5.12.8
yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2
