CVE-2026-43980: Zenitram Malla
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can set a malicious node name that executes JavaScript in the browser of every Malla dashboard visitor. Commit 4086e2b5f61615a813b70b25bc76095083552135 fixes the issue.
Affected products
- Zenitram Malla: before 4086e2b5f61615a813b70b25bc76095083552135 (fixed in 4086e2b5f61615a813b70b25bc76095083552135)
Published 2026-08-21. Last modified 2026-09-09.