Description
The wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (escapeMarkup: false). Any output the victim renders - a cat‘d file, a tailed log, an SSH MOTD, a curl response - that contains \x1b[5i...:...\x1b[4i runs script in the wetty origin and types attacker-chosen keystrokes into the victim’s SSH session.
Recommendation
Update the wetty package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.4
- Patched version(s): 3.0.4
References
Related Issues
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State - CVE-2026-42573
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
You might also like:
- Tags:
- npm
- wetty
Anything's wrong? Let us know Last updated on July 01, 2026


