PT-2026-71081 · Prowler · Prowler

CVE-2026-73262

·

Published

2026-08-12

·

Updated

2026-09-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Prowler versions prior to 5.37.0
Description The HTML output formatter in the file prowler/lib/outputs/html/html.py fails to perform HTML escaping when inserting finding.resource tags into generated reports. These tags are assembled using the unroll dict() and parse html string() functions. This allows a cloud principal with permissions to modify scanned resource tags to inject malicious HTML or JavaScript, which then executes in the browser of any user who opens the report. This is a stored cross-site scripting (XSS) issue, where a script is permanently stored on the server or in a database and served to other users.
Recommendations Update to version 5.37.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73262
GHSA-C2JG-2778-GGM4
PYSEC-2026-3907
PYSEC-2026-3908

Affected Products

Prowler