Cross-site scripting in Mongoose - CVE-2026-73254
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to cross-site scripting in the printdirentry() directory entry renderer when rendering directory listings with unescaped filenames. A remote attacker can create a file with a specially crafted filename to execute arbitrary script in a victim\'s browser.
Directory listing must be enabled, and user interaction is required to browse the affected directory listing page.