CVE-2026-55566: Yamcs

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking registered plugin IDs before DOM rendering through innerHTML. A crafted URL can execute JavaScript when opened by a user. The script can read data available to the Yamcs web application and perform actions in the user context. This issue is fixed in versions 5.12.8 and 5.13.2.

Affected products

  • Yamcs Yamcs: before 5.12.8 (fixed in 5.12.8); from 5.13.0, before 5.13.2 (fixed in 5.13.2)

Published 2026-08-28. Last modified 2026-09-08.