LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
https://github.com/linuxserver/Heimdall/compare/v2.7.2...v2.7.3
https://github.com/linuxserver/Heimdall/commit/d1a96dd752ba30dc56380400dd2587d8abb8e9d1
Source: Mitre, NVD
Published: 2025-07-27
Updated: 2025-07-29
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 7.2
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Severity: High
EPSS: 0.00029