Junglewise Threat Intelligence

CVE-2026-54443: Lissy93 Dashy XSS in RSS Widget

CVE-2026-54443 · Severity: info · CVSS 5.9 · Published 2026-07-15

Technologies: Lissy93 Dashy. Vendors: Lissy93.

Executive brief

Dashy is a self-hostable dashboard used to organize and access personal web services. A security flaw in its RSS feed widget allows a malicious or compromised news feed to execute unauthorized code in a user's browser when they click on a feed item. This could lead to the theft of login sessions or sensitive information from the dashboard.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Dashy RSS Widget due to improper neutralization of URI schemes. The component `src/components/Widgets/RssFeed.vue` fails to sanitize the `link` field of RSS items when using the default `rss2json` fetch mode. An attacker who controls a subscribed RSS feed can inject a `javascript:` URI into the feed's link attribute. When a user clicks the rendered title or 'Read More' link, the malicious script executes within the context of the Dashy origin. This can be used to exfiltrate session tokens or perform actions on behalf of the user. The issue is resolved in version 3.2.0.

Affected products

  • lissy93 Dashy >= 1.9.4, < 3.2.0

Timeline

  • 2026-03-30: patched: Version 3.2.0 released
  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: CVE published to NVD

References

Related threats