Executive brief
Malla is a dashboard used to visualize Meshtastic network data. A vulnerability allows attackers to inject malicious code into the dashboard by simply changing their device name on a public network. If an administrator or user views the dashboard, the attacker's code could steal information, redirect the user to malicious sites, or disrupt the dashboard's operation.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Malla versions 0.1.7 and earlier. The application receives Meshtastic node names (long_name and short_name) via MQTT and stores them in a SQLite database without sanitization. These names are subsequently rendered in multiple frontend templates (including traceroute_graph.html, map.html, and packet_detail.html) without proper HTML escaping. An unauthenticated remote attacker can publish a malicious NODEINFO_APP packet to a public MQTT broker to trigger the vulnerability. When a user views the Malla dashboard, the injected script executes in their browser context, potentially leading to session hijacking, phishing, or persistent denial of service. A fix is available in the project's repository.
Affected products
- zenitraM malla <= 0.1.7
Timeline
- 2026-05-30: disclosed: Initial disclosure to vendor
- 2026-06-03: advisory: GitHub Advisory published