๐Ÿ” CVE Alert

CVE-2026-49864

UNKNOWN 0.0

wetty vulnerable to DOM XSS via file-download filename

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\x1b[5i...:...\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session. Version 3.0.4 fixes the issue.

CWE CWE-79
Vendor butlerx
Product wetty
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for butlerx wetty

Be the first to know when new unknown vulnerabilities affecting butlerx wetty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

butlerx / wetty
< 3.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/butlerx/wetty/security/advisories/GHSA-p26j-h7wj-r568