HTML Injection Risk in Prowler Cloud Security Platform
CVE-2026-73262
5.4MEDIUM
What is CVE-2026-73262?
Prowler, a cloud security platform, had a vulnerability where its HTML output formatter allowed unescaped HTML and JavaScript to be inserted into generated reports. This arose from the processing of resource tags without proper HTML escaping. A malicious user with access to modify these resource tags could embed harmful scripts that execute upon report access by others. This issue has been resolved in version 5.37.0. Users are strongly advised to upgrade to this version to mitigate risks associated with potential HTML injection attacks.
Affected Version(s)
prowler < 5.37.0
