A stored cross-site scripting flaw tracked as CVE-2026-63135 was disclosed in YOURLS, affecting versions 1.5.1 through 1.10.3. The vulnerability allows an unauthenticated attacker to place malicious JavaScript in a crafted HTTP Referer header, which YOURLS logs and later renders in shortened-URL statistics pages. When an administrator views those stats, the attacker-controlled value can execute in the browser because referrer data was interpolated into inline Google Charts JavaScript without proper escaping.
The issue was fixed in YOURLS 1.10.4 through security changes merged under pull request #4107 and commit e1e93476655107e6caab34e52259eb1c91079ec7. The patch strengthens yourls_get_domain() with stricter host validation, rejects malformed and unsafe inputs including javascript: and data: URIs, and adds escaping in favicon URL generation and JavaScript data table construction. The reported impact includes administrator session hijacking, redirect manipulation, and theft of the admin's static API signature token; the flaw is mapped to CWE-79 and carries a CVSS v3.1 score of 8.2.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The coordinated disclosure states that the fixed YOURLS release 1.10.4 was published on 2026-05-21, addressing the stored XSS vulnerability later identified as CVE-2026-63135. The flaw affected versions 1.5.1 through 1.10.3.
YOURLS merged commit e1e9347 titled "Prevent XSS in stat pages through referrers," adding escaping in JavaScript chart generation, stricter domain validation, and new tests. The commit was authored and merged on May 21, 2026.
YOURLS tracked the referrer-based XSS issue in pull request #4107, marked it as verified, applied a security label, and added it to the 1.10.4 milestone. These triage actions are explicitly dated May 20, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.