Cross-site scripting in HFS - CVE-2026-61504
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in basic directory listings when rendering a crafted filename. A remote user can create a file with a malicious filename to execute arbitrary script in a victim's browser.
User interaction is required to view the affected basic directory listing.