THREAT OPS › Threat News › [GHSA] GHSA-c2jg-2778-ggm4 (medium) — Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
[GHSA] GHSA-c2jg-2778-ggm4 (medium) — Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
GHSA-c2jg-2778-ggm4 Severity: medium CVE: CVE-2026-73262
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
## Summary
Prowler's HTML output formatter inserts `finding.resource_tags` into the generated report without HTML escaping. A cloud principal who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag. When ano
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- 329dfdf8e6cb8bc0424fb54b6595408e20969782sha1
- CVE-2026-73262cve
Original source: https://github.com/advisories/GHSA-c2jg-2778-ggm4