CVE-2024-44731

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.

Published 2024-10-11. Last modified 2026-06-17.