THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c2jg-2778-ggm4 (medium) — Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

[GHSA] GHSA-c2jg-2778-ggm4 (medium) — Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

highgithub_advisoriesPublished 2026-09-08

GHSA-c2jg-2778-ggm4 Severity: medium CVE: CVE-2026-73262

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

## Summary

Prowler's HTML output formatter inserts `finding.resource_tags` into the generated report without HTML escaping. A cloud principal who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag. When ano

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c2jg-2778-ggm4