VYPR

wetty

by Butlerx

CVEs (1)

  • CVE-2026-49864HigAug 13, 2026
    risk 0.56cvss epss

    wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a…