{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yourls--1.5.1--1.10.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-63135"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YOURLS (\u003e= 1.5.1, \u003c= 1.10.3)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","stored-xss","cve-2026-63135"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eYOURLS versions 1.5.1 through 1.10.3 are vulnerable to stored cross-site scripting (XSS) resulting from improper sanitization of the HTTP 'Referer' header. An unauthenticated attacker can supply a malicious 'Referer' header to a short URL, which is subsequently logged by the application. When an administrator or authorized user views the statistics page for that short URL, the malicious payload is embedded into Google Charts JavaScript without proper escaping of string metacharacters. This vulnerability is reachable in default private installations when statistics are viewed by an authenticated user, as well as in installations with the 'YOURLS_PRIVATE_INFOS' configuration set to 'false'. Successful exploitation allows for the execution of arbitrary JavaScript within the origin of the YOURLS administration panel, potentially leading to unauthorized administrative actions and sensitive information disclosure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts an HTTP request containing a malicious 'Referer' header (e.g., \u0026quot;http://x',1],['marker',alert(1)],['z.tld/path\u0026quot;).\u003c/li\u003e\n\u003cli\u003eThe attacker triggers a request for an existing short URL on the target YOURLS instance using the crafted 'Referer' header.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eyourls_log_redirect\u003c/code\u003e function processes the request and stores the unsanitized (but truncated) 'Referer' header in the application's database.\u003c/li\u003e\n\u003cli\u003eAn authenticated administrator navigates to the statistics page (e.g., \u003ccode\u003e\u0026lt;keyword\u0026gt;+\u003c/code\u003e) for the targeted short URL.\u003c/li\u003e\n\u003cli\u003eThe application extracts the domain from the logged referrers and passes it to \u003ccode\u003eyourls_stats_pie\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eyourls_google_array_to_data_table\u003c/code\u003e function concatenates the malicious referrer domain directly into the Google Charts JavaScript array without sanitization.\u003c/li\u003e\n\u003cli\u003eThe administrator's browser executes the injected JavaScript payload within the session context.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the privileged session to perform actions such as creating/deleting links, modifying destinations, or stealing API tokens.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary JavaScript execution within the authenticated session of a YOURLS administrator. An attacker can use this access to perform privileged actions, including modifying or deleting existing short-link destinations to facilitate phishing or malware distribution, and accessing sensitive administrative tools. Furthermore, the XSS can be used to extract the administrative API signature token from \u003ccode\u003e/admin/tools.php\u003c/code\u003e, allowing for persistent, passwordless API access to the YOURLS instance until the secret is rotated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading all YOURLS instances to a patched version that correctly escapes JavaScript string metacharacters in the statistics generation logic. Until an upgrade can be performed, monitor web server logs for suspicious 'Referer' headers containing characters indicative of XSS attempts, such as single quotes, square brackets, or parentheses. If logs reveal evidence of attempted exploitation, rotate administrative API tokens immediately and audit the current short-link inventory for unauthorized modifications.\u003c/p\u003e\n","date_modified":"2026-08-22T01:17:10Z","date_published":"2026-08-22T01:17:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-yourls-xss/","summary":"The YOURLS URL shortener is vulnerable to stored cross-site scripting (XSS) via the Referer header, allowing unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser context.","title":"Stored XSS in YOURLS via Referer Header","url":"https://feed.craftedsignal.io/briefs/2026-08-yourls-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - YOURLS (\u003e= 1.5.1, \u003c= 1.10.3)","version":"https://jsonfeed.org/version/1.1"}