PatchSiren

hashgraph CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM hashgraph CVE published 2026-06-18

CVE-2026-22674

CVE-2026-22674 details a stored cross-site scripting vulnerability in Hashgraph Guardian through version 3.6.0. The vulnerability allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary [truncated]

HIGH hashgraph CVE published 2026-04-09

CVE-2026-39911

CVE-2026-39911 is a high-severity vulnerability in Hashgraph Guardian, a product by Hedera, that allows authenticated Standard Registry users to execute arbitrary code. The vulnerability exists in the Custom Logic policy block worker, where user-supplied JavaScript expressions are passed directly to the Node.js Function() constructor without isolation. This enables attackers to import native Node.js modul [truncated]