Untriaged
Permalink
CVE-2026-73254
5.4 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
Mongoose: Stored XSS via unescaped filenames in directory listing
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the href but inserts the raw filesystem filename into the HTML link text. The browser executes the injected markup in the Mongoose origin, which can expose session data or permit actions as the victim. This issue is fixed in version 7.22.
References
-
https://github.com/cesanta/mongoose/security/advisories/GHSA-5g6j-m3pv-4f7g x_refsource_CONFIRM
-
https://github.com/cesanta/mongoose/pull/3611 x_refsource_MISC
-
https://github.com/cesanta/mongoose/releases/tag/7.22 x_refsource_MISC
Affected products
mongoose
- ==< 7.22
Package maintainers
-
@wegank Weijia Wang <contact@weijia.wang>