logo

Stored XSS Vulnerability in RustFS Console Puts S3 Admin Credentials at Risk

ID: 8a5ca6f3-2de8-5aa8-81cf-861e5b8f3a82

STIX ID: report--8a5ca6f3-2de8-5aa8-81cf-861e5b8f3a82

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive Summary:** RustFS Console contains a critical Stored XSS (CVE-2026-27822, CVSS 10.0) where previewing a file with a forged Content-Type in a same-origin iframe can execute attacker-controlled JavaScript, allowing theft of S3 admin credentials from localStorage and enabling full account takeover; users should upgrade to 1.0.0-alpha.83 and implement origin separation, CSP, and X-Content-Type-Options to mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.