Junglewise Threat Intelligence

CVE-2026-4765: RD Station Conversas Tallos Chat stored XSS in name parameter

CVE-2026-4765 · Severity: info · CVSS 5.1 · Published 2026-07-13

Executive brief

RD Station Conversas Tallos Chat, a professional customer service and sales tool, contains a security flaw in its chat initialization process. An attacker can submit a malicious name that, when viewed by a support agent, executes unauthorized code in the agent's browser. This could allow an attacker to hijack support sessions or access sensitive customer interaction data.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'name' parameter of the Tallos Chat initialization process. The root cause is improper sanitization of user-supplied input during the chat setup. An unauthenticated remote attacker can inject malicious scripts that are stored on the server and subsequently executed in the context of a support agent's session when they join the conversation. This allows for arbitrary JavaScript execution, potentially leading to session hijacking or unauthorized actions within the application. As of the advisory date, no patch has been reported.

Affected products

  • RD Station Conversas Tallos Chat All versions

Timeline

  • 2026-07-13: disclosed: Initial disclosure by INCIBE-CERT
  • 2026-07-13: advisory: CVE-2026-4765 published

References