Retour au portail de sécurité
XSS in Trezor Connect legacy versions
Signalé sur February 7, 2023
We were notified by Jun Kokatsu that there were XSS vulnerabilities, similar to those reported in August 2020. These vulnerabilities were present in the deprecated versions of Trezor Connect that were however still available to legacy implementations on urls https://trezor.connect.io/5, https://trezor.connect.io/6 and https://trezor.connect.io/7.
This issue posed a potential threat of a phishing attack which could gain more trust by changing content served from the trezor.io domain. The issue was fixed by removing those affected versions completely.
Signalé par Jun Kokatsu
Trezor Connect
Vulnérabilités résolues
Signalé par la communauté. Examiné. Résolu. Parce que votre sécurité n’est jamais optionnelle.
- Biometric Verification bypassed in Trezor Suite with external monitor9 mars 2026
- Insufficient entropy on Trezor Model One with 12/18 words6 février 2026
- Inability to cancel certain flows on pre-production firmware31 octobre 2025
- Fix side-channel in BIP-39 mnemonic processing when unlocked24 septembre 2025
- Donjon's Trezor Safe 3 evaluation12 novembre 2024
- Missing confirmation in the ECDHSessionKey call26 novembre 2023