CVE-2026-73254
Mongoose: Stored XSS via unescaped filenames in directory listing
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the href but inserts the raw filesystem filename into the HTML link text. The browser executes the injected markup in the Mongoose origin, which can expose session data or permit actions as the victim. This issue is fixed in version 7.22.
| CWE | CWE-79 |
| Vendor | cesanta |
| Product | mongoose |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for cesanta mongoose
Be the first to know when new medium vulnerabilities affecting cesanta mongoose are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
cesanta / mongoose
< 7.22
References
github.com: https://github.com/cesanta/mongoose/security/advisories/GHSA-5g6j-m3pv-4f7g github.com: https://github.com/cesanta/mongoose/pull/3611 github.com: https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71 github.com: https://github.com/cesanta/mongoose/releases/tag/7.22