What is CVE-2026-72570?
This is a stored XSS vulnerability in cube-root/directory-serve up to version 1.3.7. An attacker can inject JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. Users should upgrade to the latest version to mitigate the risk.
Azərbaycanca: Bu, cube-root/directory-serve (1.3.7 versiyasına qədər) alətində aşkarlanmış stored XSS zəifliyidir. Təcavüzkar xüsusi simvollar (HTML atributlarını qıran) daxil edilmiş fayl adı ilə fayl yükləyərək veb interfeysə JavaScript kodu yeridə bilər. İstifadəçilər zərərli fayl adı ilə qarşılaşdıqda kod işə düşə bilər, buna görə də dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which software and version is affected by CVE-2026-72570?
This stored XSS vulnerability affects cube-root/directory-serve up to version 1.3.7.
How can an attacker exploit CVE-2026-72570?
An attacker can inject JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.