Executive brief
Fathom Lite is an open-source web analytics tool used to track website traffic. A security flaw allows unauthenticated attackers to inject malicious code into the administrator's dashboard by sending specially crafted data to the tracking system. If an administrator clicks on a poisoned entry in their "Top Pages" report, the attacker could hijack their session, steal data, or take full control of the analytics account.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Fathom Lite through version 1.3.1 due to insufficient validation in the `parseHostname` and `parsePathname` functions. An unauthenticated attacker can send a crafted request to the `/collect` endpoint containing a `javascript:` URI in the hostname field and a newline-prefixed payload in the pathname field. These values are stored without sanitization and later rendered as an `href` attribute in an anchor tag within the "Top Pages" section of the authenticated dashboard. When an operator clicks the malicious link, the JavaScript executes in the context of the dashboard's origin, potentially leading to session hijacking and full account takeover. The vulnerability is facilitated by the use of Preact 8, which does not automatically sanitize `javascript:` URIs.
Affected products
- Fathom Fathom Lite through 1.3.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory