CVE-2026-54443

NONE
CVSS v3
CVSS v2
0.23% EPSS (exploit probability)
CWE-80CWE

Description

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references