CVE 8.2 HIGH

Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink_CVE-2025-59430

8.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

Description

Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLink.openLink function enables the execution of arbitrary JavaScript code within the context of the parent page. This is technically indistinguishable from a real page at the rendering level and allows access to the parent page DOM, storage, session, and cookies. If the attacker can specify customIframeId, they can hijack the source of existing iframes. This issue has been patched in version 3.3.2.

Basic Information

ID CVE-2025-59430
Source GitHub_M
Published Sep 22, 2025 at 18:47
Modified Sep 22, 2025 at 19:43

Affected Product

Vendor FrontFin
Product mesh-web-sdk
Version < 3.3.2
Affected Versions FrontFin mesh-web-sdk < 3.3.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.