CVE-2026-65697 | usefathom Fathom up to 1.3.1 Analytics Collection Endpoint parseHostname/parsePathname hostname/pathname cross site scripting
A vulnerability classified as problematic was found in usefathom Fathom up to 1.3.1. This issue affects the function parseHostname/parsePathname of the component Analytics Collection Endpoint. Such manipulation of the argument hostname/pathname leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is referenced as CVE-2026-65697. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More