CVE-2026-73262: Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler’s HTML output formatter inserts finding.resource_tags into the generated report without HTML escaping. A cloud principal who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag. When another user opens the generated Prowler HTML report, the payload executes in the report page.
References
- github.com/advisories/GHSA-c2jg-2778-ggm4
- github.com/prowler-cloud/prowler/commit/6db407ed3c17d4c73a8f619fdb30580c8465027f
- github.com/prowler-cloud/prowler/pull/12221
- github.com/prowler-cloud/prowler/releases/tag/5.37.0
- github.com/prowler-cloud/prowler/security/advisories/GHSA-c2jg-2778-ggm4
- nvd.nist.gov/vuln/detail/CVE-2026-73262
Code Behaviors & Features
Detect and mitigate CVE-2026-73262 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →