MEDIUM
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Published Aug 12, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.30%
Description
Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0.
Affected products
-
- Version < 5.37.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Prowler-Cloud | Prowler | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57222 Advisory
- https://github.com/advisories/GHSA-c2jg-2778-ggm4 Advisory
- https://github.com/prowler-cloud/prowler/commit/6db407ed3c17d4c73a8f619fdb30580c8465027f x_refsource_MISC
- https://github.com/prowler-cloud/prowler/pull/12221 x_refsource_MISC
- https://github.com/prowler-cloud/prowler/releases/tag/5.37.0 x_refsource_MISC
- https://github.com/prowler-cloud/prowler/security/advisories/GHSA-c2jg-2778-ggm4 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-73262
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57222 | Advisory | |
| https://github.com/advisories/GHSA-c2jg-2778-ggm4 | Advisory | |
| https://github.com/prowler-cloud/prowler/commit/6db407ed3c17d4c73a8f619fdb30580c8465027f | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/pull/12221 | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/releases/tag/5.37.0 | x_refsource_MISC | |
| https://github.com/prowler-cloud/prowler/security/advisories/GHSA-c2jg-2778-ggm4 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73262 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 12, 2026
Reserved Aug 11, 2026
Link CVE-2026-73262
CISA Vulnrichment
Updated Aug 12, 2026
ENISA EUVD
EUVD-2026-57222 GHSA-C2JG-2778-GGM4 Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 12, 2026
Exploited since n/a
Link EUVD-2026-57222