PT-2026-31465 · Yamato Security+1 · Hayabusa
CVE-2026-40028
·
Published
2026-04-08
·
Updated
2026-04-08
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hayabusa versions prior to 3.8.0
Description
A cross-site scripting (XSS) issue exists in the HTML report output. This occurs when a user scans JSON-exported logs containing malicious content in the
Computer field. An attacker can inject JavaScript into this field, which then executes within the forensic examiner's browser session during the viewing of the generated HTML report, potentially resulting in code execution or information disclosure.Recommendations
Update to version 3.8.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hayabusa