Medium severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-54443
CVE-2026-54443
Description
Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.