CVE-2026-22674 details a stored cross-site scripting vulnerability in Hashgraph Guardian through version 3.6.0. The vulnerability allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary [truncated]
CVE-2026-39911 is a high-severity vulnerability in Hashgraph Guardian, a product by Hedera, that allows authenticated Standard Registry users to execute arbitrary code. The vulnerability exists in the Custom Logic policy block worker, where user-supplied JavaScript expressions are passed directly to the Node.js Function() constructor without isolation. This enables attackers to import native Node.js modul [truncated]