PT-2026-71081 · Prowler · Prowler
CVE-2026-73262
·
Published
2026-08-12
·
Updated
2026-09-10
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Prowler versions prior to 5.37.0
Description
The HTML output formatter in the file
prowler/lib/outputs/html/html.py fails to perform HTML escaping when inserting finding.resource tags into generated reports. These tags are assembled using the unroll dict() and parse html string() functions. This allows a cloud principal with permissions to modify scanned resource tags to inject malicious HTML or JavaScript, which then executes in the browser of any user who opens the report. This is a stored cross-site scripting (XSS) issue, where a script is permanently stored on the server or in a database and served to other users.Recommendations
Update to version 5.37.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prowler