8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Description
Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLink.openLink function enables the execution of arbitrary JavaScript code within the context of the parent page. This is technically indistinguishable from a real page at the rendering level and allows access to the parent page DOM, storage, session, and cookies. If the attacker can specify customIframeId, they can hijack the source of existing iframes. This issue has been patched in version 3.3.2.
Basic Information
ID
CVE-2025-59430
Source
GitHub_M
Published
Sep 22, 2025 at 18:47
Modified
Sep 22, 2025 at 19:43
Affected Product
Vendor
FrontFin
Product
mesh-web-sdk
Version
< 3.3.2
Affected Versions
FrontFin mesh-web-sdk < 3.3.2
CWE Classification
References
- github.com /FrontFin/mesh-web-sdk/security/advisories/GHSA-vh3f-qppr-j97f
- github.com /FrontFin/mesh-web-sdk/pull/124
- github.com /FrontFin/mesh-web-sdk/commit/7f22148516d58e21a8b7670dde927d614c0d15c2
- github.com /FrontFin/mesh-web-sdk/blob/cf013b85ab95d64c63cbe46d6cb14695474924e7/packages/link/src/Link.ts