Voltar para o portal de segurança
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Reportado em March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Reportado por Vipul Sahu
Vulnerabilidades resolvidas
Reportado pela comunidade. Investigado. Resolvido. Porque sua segurança nunca é opcional.
- THP pairing could be completed without the pairing code22 de junho de 2026
- Desktop update could install before signature verification completed16 de junho de 2026
- Solana account-creation confirmation completeness14 de junho de 2026
- Solana signing display improvement12 de junho de 2026
- Coordination fee cap shown on CoinJoin authorization3 de junho de 2026
- Solana token-transfer recipient spoofing via Address Lookup Table reference1 de junho de 2026