Yamcs 是一个任务控制框架。在 5.12.8 和 5.13.2 之前的版本中,Yamcs 在处理来自 URL 路由的攻击者可控数据时,在通过 进行 DOM 渲染之前,未先检查已注册的插件 ID。相关的处理代码位于 、 和 。攻击者可以构造一个恶意 URL,当用户打开该 URL 时,其中内嵌的 JavaScript 代码将被执行。该脚本能够读取 Yamcs Web 应用中可用的数据,并在用户的上下文中执行操作。此问题已在版本 5.12.8 和 5.13.2 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55565 | 9.9 CRITICAL | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled |
| CVE-2026-55559 | 9.8 CRITICAL | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55552 | 7.5 HIGH | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55545 | 6.5 MEDIUM | Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfor |
| CVE-2026-55549 | 6.5 MEDIUM | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
No comments yet