CVE-2026-54443 MEDIUM

CVE-2026-54443: Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Vendor Lissy93
Product dashy
Weakness CWE-80 · XSS · basic
Published July 15, 2026
Last update July 15, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

Key dates

02Disclosure timeline

July 15, 2026 CVE published
July 15, 2026 Record updated

Related vulnerabilities

04Related CVE