Yamcs 是一个任务控制框架。在 5.9.4 版本之前,Yamcs 的 端点会将攻击者可控的 参数直接反射到 模板中,且未通过 和 进行充分的 HTML 转义。攻击者可以构造一个特殊的授权 URL,当 Yamcs 用户打开该 URL 时,其中嵌入的 JavaScript 代码将被执行。该脚本能够访问浏览器中存储的认证信息,并将其传输给攻击者,从而导致账户被盗。此问题已在 5.9.4 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55565 | 9.9 CRITICAL | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled |
| CVE-2026-55559 | 9.8 CRITICAL | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55552 | 7.5 HIGH | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55545 | 6.5 MEDIUM | Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfor |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
| CVE-2026-55566 | 4.3 MEDIUM | Yamcs: DOM XSS in Extension Routing |
No comments yet