Retour au portail de sécurité
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Signalé sur March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Signalé par Vipul Sahu
Vulnérabilités résolues
Signalé par la communauté. Examiné. Résolu. Parce que votre sécurité n’est jamais optionnelle.
- Unauthenticated Remote DoS via xpub Change-Index Amplification19 mai 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp Array19 mai 2026
- Cross-Origin Popup Takeover in Trezor Connect popup3 mai 2026
- EIP-712 Domain Spoofing via Double-Fetch21 mars 2026
- Open redirect on affiliate page20 mars 2026
- Biometric Verification bypassed in Trezor Suite with external monitor9 mars 2026