Back to security portal

Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection

Reported on March 25, 2026

A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.

Reported by Vipul Sahu