Zurück zum Sicherheitsportal
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Gemeldet auf March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Gemeldet durch Vipul Sahu
Behobene Sicherheitslücken
Gemeldet durch Community. Untersucht. Gelöst. Weil deine Sicherheit nie optional ist.
- Open redirect on affiliate page20. März 2026
- Biometric Verification bypassed in Trezor Suite with external monitor9. März 2026
- Insufficient entropy on Trezor Model One with 12/18 words6. Februar 2026
- Bug in multisig verification10. Januar 2026
- Inability to cancel certain flows on pre-production firmware31. Oktober 2025
- Fix side-channel in BIP-39 mnemonic processing when unlocked24. September 2025