Junglewise Threat Intelligence

CVE-2025-59430: Mesh Connect JS SDK cross-site scripting in createLink.openLink

CVE-2025-59430 · Severity: low · CVSS 3.1 · Published 2025-09-22

Vendors: npm.

Executive brief

The Mesh Connect Web Link SDK is a JavaScript library used by financial applications to embed secure iframe-based payment and transaction flows. A cross-site scripting vulnerability in the createLink.openLink function allows attackers to inject malicious JavaScript code that executes with access to the parent page's DOM, cookies, session storage, and potentially sensitive transaction data—enabling credential theft, transaction hijacking, or wallet compromise.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw caused by insufficient URL protocol validation in the createLink.openLink function. The function accepts base64-encoded URLs, decodes them, and directly assigns the result to an iframe's src attribute without sanitizing the URL protocol. An attacker can craft a malicious base64-encoded payload using a javascript: protocol (e.g., javascript:alert(document.domain)//), which the function will decode and execute in the iframe context, granting access to the parent page's DOM, cookies, and session storage. The attack requires user interaction (clicking the OpenLink button) and is network-accessible. Patches are available in version 3.3.2 and later.

Affected products

  • FrontFin @meshconnect/web-link-sdk <3.3.2

Timeline

  • 2025-09-22: disclosed: Advisory published
  • 2025-09-22: patched: Version 3.3.2 released with fix

References