EIP-2026-100634

PRE-CVE

Yetihost Helm 3.2.10 - Multiple Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100634. PoCs published by Aria-Security Team.

AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in Helm by providing specific URLs with injected script tags. These URLs target various input parameters in different pages of the application, confirming the lack of proper input sanitization.

Description

Yetihost Helm 3.2.10 - Multiple Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aria-Security Team · textwebappsasp
https://www.exploit-db.com/exploits/29041

The exploit demonstrates multiple XSS vulnerabilities in Helm by providing specific URLs with injected script tags. These URLs target various input parameters in different pages of the application, confirming the lack of proper input sanitization.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Helm version 3.2.10
No auth needed
Prerequisites: Access to the vulnerable Helm web application
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026