PT-2026-31465 · Yamato Security+1 · Hayabusa

CVE-2026-40028

·

Published

2026-04-08

·

Updated

2026-04-08

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hayabusa versions prior to 3.8.0
Description A cross-site scripting (XSS) issue exists in the HTML report output. This occurs when a user scans JSON-exported logs containing malicious content in the Computer field. An attacker can inject JavaScript into this field, which then executes within the forensic examiner's browser session during the viewing of the generated HTML report, potentially resulting in code execution or information disclosure.
Recommendations Update to version 3.8.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40028

Affected Products

Hayabusa