Impact
Dashy, a self‑hosted personal dashboard, was found to perform an unsafe assignment of the workspace URL query parameter directly to flaw allows a crafted javascript: URL to be executed in the context of the Dashy origin, enabling the attacker to read same‑origin browser data, manipulate the dashboard DOM, and issue requests as the logged‑in user Cross‑Site Scripting vulnerability (CWE‑79).
Affected Systems
The affected product is Dashy from vendor lissy93, with all releases before 4.3.7 vulnerable. Users running these earlier versions should be aware that any logged‑in user who opens a malicious workspace link can trigger the script.
Risk and Exploitability
The reported CVSS score of 3.9 indicates low overall severity, and the EPSS score is <1%, with the vulnerabilityoitation requires user authentication and the ability to supply a crafted link, so the risk is confined to authenticated users within the instance; nevertheless the potential for data theft warrants immediate remediation.
OpenCVE Enrichment