Description
The wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (escapeMarkup: false). Any output the victim renders - a cat‘d file, a tailed log, an SSH MOTD, a curl response - that contains \x1b[5i...:...\x1b[4i runs script in the wetty origin and types attacker-chosen keystrokes into the victim’s SSH session.
Recommendation
Update the wetty package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.4
- Patched version(s): 3.0.4
References
Could your website be exposed too?
SmartScanner can check your website for wetty vulnerable to DOM XSS via file-download filename and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State - CVE-2026-42573
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959


