Low severity3.9NVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
CVE-2026-55592
CVE-2026-55592
Description
Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without scheme validation. If a logged-in user opens a crafted workspace link containing a javascript: URL, JavaScript runs on the Dashy origin and can read same-origin browser data, interact with the Dashy DOM, and send requests as the victim. This issue is fixed in version 4.3.7.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.