Back to security portal
Reflected cross-site scripting (XSS) vulnerability on connect.trezor.io via hash fragment script injection
Reported on March 25, 2026
A vulnerability was discovered in the documentation endpoint of Trezor Connect, where a URL parameter could be abused to load and execute arbitrary JavaScript within the trusted domain. This issue resulted in a reflected cross-site scripting (XSS) vulnerability, allowing malicious scripts to run in the context of the official site.
Reported by Vipul Sahu
Resolved vulnerabilities
Reported by community. Investigated. Resolved. Because your security is never optional.
- Unauthenticated Remote DoS via xpub Change-Index AmplificationMay 19, 2026
- Unauthenticated Remote Memory Exhaustion via Unbounded Timestamp ArrayMay 19, 2026
- Cross-Origin Popup Takeover in Trezor Connect popupMay 3, 2026
- EIP-712 Domain Spoofing via Double-FetchMarch 21, 2026
- Open redirect on affiliate pageMarch 20, 2026
- Biometric Verification bypassed in Trezor Suite with external monitorMarch 9, 2026