CVE-2026-43980: Zenitram Malla

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can set a malicious node name that executes JavaScript in the browser of every Malla dashboard visitor. Commit 4086e2b5f61615a813b70b25bc76095083552135 fixes the issue.

Affected products

  • Zenitram Malla: before 4086e2b5f61615a813b70b25bc76095083552135 (fixed in 4086e2b5f61615a813b70b25bc76095083552135)

Published 2026-08-21. Last modified 2026-09-09.