A stored cross-site scripting vulnerability in prowler and prowler-cloud, identified as CVE-2026-73262 with a CVSS score of 5.4, exists in Prowler's HTML output formatter due to the insertion of unescaped cloud resource tags into generated reports. An attacker who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag, allowing them to read and modify the report DOM, alter displayed findings, and interact with any same-origin local or hosted report content available to the browser when another user opens the generated Prowler HTML report. This vulnerability can undermine trust in generated security findings and expose data contained in the report page. The flaw is classified as a stored cross-site scripting vulnerability, with a network attack vector and user interaction required for exploitation, potentially impacting the integrity and confidentiality of sensitive information contained in security reports.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A stored cross-site scripting vulnerability in prowler and prowler-cloud, identified as CVE-2026-73262 with a CVSS score of 5.4, exists in Prowler's HTML output formatter due to the insertion of unescaped cloud resource tags into generated reports. An attacker who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag, allowing them to read and modify the report DOM, alter displayed findings, and interact with any same-origin local or hosted report content available to the browser when another user opens the generated Prowler HTML report. This vulnerability can undermine trust in generated security findings and expose data contained in the report page. The flaw is classified as a stored cross-site scripting vulnerability, with a network attack vector and user interaction required for exploitation, potentially impacting the integrity and confidentiality of sensitive information contained in security reports.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]