PT-2026-61601 · Frogman · Frogman

CVE-2026-46516

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Frogman versions prior to 1.6.6
Description The chat-console markdown formatter in the formatMarkdown() function within assets/js/chat.js incorrectly inserts regex capture groups as raw HTML for inline code, bold, markdown links, and download links. This allows an attacker to inject HTML or JavaScript payloads through user-controlled fields such as extension names, ring-group descriptions, IVR names, and queue descriptions. When another administrator views these responses via the Frogman chat, the payload executes within the viewer's session using their specific permissions.
Recommendations Update to version 1.6.6.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46516
GHSA-7QVV-VGW9-RCXG

Affected Products

Frogman