๐Ÿ” CVE Alert

CVE-2026-73254

MEDIUM 5.4

Mongoose: Stored XSS via unescaped filenames in directory listing

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the href but inserts the raw filesystem filename into the HTML link text. The browser executes the injected markup in the Mongoose origin, which can expose session data or permit actions as the victim. This issue is fixed in version 7.22.

CWE CWE-79
Vendor cesanta
Product mongoose
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for cesanta mongoose

Be the first to know when new medium vulnerabilities affecting cesanta mongoose are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

cesanta / mongoose
< 7.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cesanta/mongoose/security/advisories/GHSA-5g6j-m3pv-4f7g github.com: https://github.com/cesanta/mongoose/pull/3611 github.com: https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71 github.com: https://github.com/cesanta/mongoose/releases/tag/7.22