Back

MEDIUM

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Published Aug 12, 2026

Description

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 12, 2026
Reserved Aug 11, 2026
CISA Vulnrichment
Updated Aug 12, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 12, 2026
Exploited since n/a
EUVD-2026-57222 GHSA-C2JG-2778-GGM4