---
id: CVE-2025-59430
title: Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect
summary: >-
  Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect.
  Prior to version 3.3.2, the lack of sanitization of URLs protocols in the
  createLink.openLink function enables the execution of arbitrary JavaScript
  code within…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N'
cwe:
  - CWE-79
published: '2025-09-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T16:10:00.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59430'
references:
  - url: >-
      https://github.com/FrontFin/mesh-web-sdk/blob/cf013b85ab95d64c63cbe46d6cb14695474924e7/packages/link/src/Link.ts#L441
    label: security-advisories@github.com
  - url: >-
      https://github.com/FrontFin/mesh-web-sdk/commit/7f22148516d58e21a8b7670dde927d614c0d15c2
    label: security-advisories@github.com
  - url: 'https://github.com/FrontFin/mesh-web-sdk/pull/124'
    label: security-advisories@github.com
  - url: >-
      https://github.com/FrontFin/mesh-web-sdk/security/advisories/GHSA-vh3f-qppr-j97f
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0047
epssPercentile: 0.38329
ingestedAt: '2026-10-01T18:55:42.290Z'
---

## Overview

Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLink.openLink function enables the execution of arbitrary JavaScript code within the context of the parent page. This is technically indistinguishable from a real page at the rendering level and allows access to the parent page DOM, storage, session, and cookies. If the attacker can specify customIframeId, they can hijack the source of existing iframes. This issue has been patched in version 3.3.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
