VYPR

PyPI package

malla

pkg:pypi/malla

Vulnerabilities (1)

  • CVE-2026-43980Jun 3, 2026
    affected <= 0.1.7

    Node names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can set a malicious node name that executes JavaScript in the browser of every Malla dashb