HTML Injection Risk in Prowler Cloud Security Platform
CVE-2026-73262

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73262?

Prowler, a cloud security platform, had a vulnerability where its HTML output formatter allowed unescaped HTML and JavaScript to be inserted into generated reports. This arose from the processing of resource tags without proper HTML escaping. A malicious user with access to modify these resource tags could embed harmful scripts that execute upon report access by others. This issue has been resolved in version 5.37.0. Users are strongly advised to upgrade to this version to mitigate risks associated with potential HTML injection attacks.

Affected Version(s)

prowler < 5.37.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.