MEDIUM 6.3 NVD
CVE-2026-43980
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name)
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can set a malicious node name that executes JavaScript in the browser of every Malla dashboard visitor. Commit 4086e2b5f61615a813b70b25bc76095083552135 fixes the issue.
References
- https://github.com/pypa/advisory-database/tree/main/vulns/malla/PYSEC-2026-2618.yaml
- https://github.com/zenitraM/malla/commit/4086e2b5f61615a813b70b25bc76095083552135
- https://github.com/zenitraM/malla/security/advisories/GHSA-ch57-39q2-4crm
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-08-21 via NVD.
vulnfeed aggregates 11685 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.