Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers
ID: c2306adb-71d2-5851-b519-340bdff2fafd
STIX ID: report--c2306adb-71d2-5851-b519-340bdff2fafd
Feed Name: securityonline.info
Threat Score
RustFS (pre-1.0.0-alpha.82) contains a critical stored XSS (CVE-2026-27822, CVSS 9.1) in its file preview modal that allows an attacker to upload a file with a manipulated Content-Type to execute script in an iframe, access the console's localStorage, and steal S3 administrative credentials—resulting in full account takeover; upgrade to 1.0.0-alpha.83 and apply origin separation, CSP, and X-Content-Type-Options:nosniff as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
