#VU125043 Cross-site scripting in emissary - CVE-2026-35571
Published: April 7, 2026
emissary
National Security Agency
Description
The vulnerability allows a remote user to perform cross-site scripting.
The vulnerability exists due to improper input validation in the nav.mustache navigation template when rendering configuration-controlled link values into href attributes. A remote privileged user can inject a javascript: URI into a navigation item link to perform cross-site scripting.
User interaction is required, as a victim must click the malicious navigation link in the web interface.