{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/governikus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AusweisApp2"],"_cs_severities":["low"],"_cs_tags":["web-vulnerability","xss"],"_cs_type":"threat","_cs_vendors":["Governikus"],"content_html":"\u003cp\u003eA Cross-Site Scripting (XSS) vulnerability exists in the Governikus AusweisApp2 software, allowing a remote, unauthenticated attacker to inject and execute malicious scripts. XSS attacks generally target the client-side session of a user by injecting scripts into a trusted application's context. This vulnerability potentially allows an attacker to steal session cookies, capture user input, or perform actions on behalf of the authenticated user within the AusweisApp2 interface. The risk is considered low, but users are advised to monitor for updates from Governikus to address this security flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could allow unauthorized script execution within the context of the AusweisApp2 application on a victim's machine. This may lead to the compromise of user-specific data managed by the application or unauthorized interaction with the identity services the software facilitates. No specific victim statistics or active exploitation reports are provided in the source documentation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor official Governikus update channels for patches addressing this XSS vulnerability in AusweisApp2.\u003c/li\u003e\n\u003cli\u003eEnsure the application is updated to the latest available version once a fix is released.\u003c/li\u003e\n\u003cli\u003eRestrict execution of untrusted external content or links while the application is active if possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T13:05:17Z","date_published":"2026-09-15T13:05:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-governikus-xss/","summary":"A vulnerability in the Governikus AusweisApp2 software allows a remote, unauthenticated attacker to execute a Cross-Site Scripting (XSS) attack.","title":"Cross-Site Scripting Vulnerability in Governikus AusweisApp2","url":"https://feed.craftedsignal.io/briefs/2026-09-governikus-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Governikus","version":"https://jsonfeed.org/version/1.1"}