CVE-2026-55592

LOW NUCLEI

Dashy: XSS in workspace url parameter

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-55592 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without scheme validation. If a logged-in user opens a crafted workspace link containing a javascript: URL, JavaScript runs on the Dashy origin and can read same-origin browser data, interact with the Dashy DOM, and send requests as the victim. This issue is fixed in version 4.3.7.

Nuclei Templates (1)

Dashy <= 4.3.6 - Reflected XSS via Workspace
MEDIUMVERIFIEDby 0x_Akoko
Shodan: title:"Dashy"
FOFA: title="Dashy"

Scores

CVSS v3 3.9
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
lissy93/dashy < 4.3.7
Published Jul 07, 2026
Tracked Since Jul 08, 2026