Impact
Dashy’s RSS widget fails to sanitize link values used in feed titles and "Read More" anchors. When an attacker controls an RSS feed and supplies a link such as javascript:alert(1), the JavaScript is rendered in the browser when a user clicks the anchor. This stored XSS runs with the Dashy origin’s privileges, allowing an attacker to steal session tokens, deface the page, or perform other client‑side attacks. The flaw directly impacts confidentiality and integrity of the affected user's session.
Affected Systems
The vulnerability affects the Dashy personal dashboard owned by lissy93. Versions from 1.9.4 up to and including 3.2.0 are impacted; the issue was resolved in the 3.2.0 release.
Risk and Exploitability
The CVSS base score of 5.9 classifies the vulnerability as moderate severity. An EPSS score of less than 1% indicates a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to supply a malicious RSS feed and for an end user to click the rendered link; thus the risk is contingent on user interaction and the availability of untrusted feed sources.
OpenCVE Enrichment