Zpět na portál zabezpečení
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Nahlášeno March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Nahlášeno Vipul Sahu
Vyřešené zranitelnosti
Nahlášeno komunitou. Prošetřeno. Vyřešeno. Protože vaše bezpečnost není nikdy volitelná.
- THP pairing could be completed without the pairing code22. června 2026
- Desktop update could install before signature verification completed16. června 2026
- Solana account-creation confirmation completeness14. června 2026
- Solana signing display improvement12. června 2026
- Coordination fee cap shown on CoinJoin authorization3. června 2026
- Solana token-transfer recipient spoofing via Address Lookup Table reference1. června 2026