Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prowler-cloud
Prowler-cloud prowler |
|
| Vendors & Products |
Prowler-cloud
Prowler-cloud prowler |
Wed, 12 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who can modify a scanned resource tag to store HTML or JavaScript that executes when another user opens the report. This issue is fixed in version 5.37.0. | |
| Title | Prowler: Stored XSS in HTML reports through unescaped cloud resource tags | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T22:12:25.308Z
Reserved: 2026-08-11T17:18:01.598Z
Link: CVE-2026-73262
Updated: 2026-08-12T22:07:28.603Z
Status : Received
Published: 2026-08-12T15:18:30.793
Modified: 2026-08-12T23:17:23.863
Link: CVE-2026-73262
No data.
OpenCVE Enrichment
Updated: 2026-08-13T00:45:02Z