Zurück zum Sicherheitsportal
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Gemeldet auf March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Gemeldet durch Vipul Sahu
Behobene Sicherheitslücken
Gemeldet durch Community. Untersucht. Gelöst. Weil deine Sicherheit nie optional ist.
- THP pairing could be completed without the pairing code22. Juni 2026
- Desktop update could install before signature verification completed16. Juni 2026
- Solana account-creation confirmation completeness14. Juni 2026
- Solana signing display improvement12. Juni 2026
- Coordination fee cap shown on CoinJoin authorization3. Juni 2026
- Solana token-transfer recipient spoofing via Address Lookup Table reference1. Juni 2026