Back

Self Cross-Site Scripting (Self-XSS) in Tallos Chat by RD Station Conversas

Published Jul 13, 2026

Description

Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation allows specially crafted JavaScript code to be injected, which is executed within the context of the user’s own session who provides the payload. The demonstrated impact is limited to the user who enters and executes the payload.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jul 13, 2026
Updated Sep 9, 2026
Reserved Mar 24, 2026
CISA Vulnrichment
Updated Jul 13, 2026
NVD
Status Deferred
Modified Sep 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Jul 13, 2026
Updated Sep 9, 2026
Exploited since n/a
EUVD-2026-43337