Kembali ke portal keamanan
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Dilaporkan pada March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Dilaporkan oleh Vipul Sahu
Kerentanan yang teratasi
Dilaporkan komunitas. Diselidiki. Diselesaikan. Karena keamanan Anda tidak pernah opsional.
- THP pairing could be completed without the pairing code22 Juni 2026
- Desktop update could install before signature verification completed16 Juni 2026
- Solana account-creation confirmation completeness14 Juni 2026
- Solana signing display improvement12 Juni 2026
- Coordination fee cap shown on CoinJoin authorization3 Juni 2026
- Solana token-transfer recipient spoofing via Address Lookup Table reference1 Juni 2026