Stored XSS Vulnerability in ka9q_ubersdr by Madpsy
CVE-2026-97723
5.4MEDIUM
What is CVE-2026-97723?
The ka9q_ubersdr application, developed by Madpsy, is susceptible to a stored cross-site scripting vulnerability. This flaw exists in the chat message rendering functionality, where user-controlled URLs in chat messages are not properly sanitized before being transformed into HTML links. As a result, malicious actors can exploit this vulnerability by embedding quotation characters to break out of the href attribute, enabling the injection of arbitrary HTML attributes. Such an exploit can facilitate the execution of arbitrary JavaScript in the browsers of other users without requiring them to click on a malicious link.
Affected Version(s)
ka9q_ubersdr 0 < 0.1.58
