{"id":"CVE-2026-61504","summary":"Rejetto HFS \u003c 3.2.1 Stored XSS via File Names in Basic Web Listing","details":"Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback \"basic\" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers with an open upload folder - can store a file whose name contains script that executes in the browser of anyone viewing the listing.","modified":"2026-08-12T03:51:37.842702232Z","published":"2026-07-13T17:23:40.045Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61504.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61504.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61504"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/rejetto-hfs-stored-xss-via-file-names-in-basic-web-listing"},{"type":"FIX","url":"https://github.com/rejetto/hfs/releases/tag/v3.2.1"},{"type":"PACKAGE","url":"https://github.com/rejetto/hfs"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rejetto/hfs","events":[{"introduced":"72b005c14cd3d11e0ef3afa3c9fa46bc07af444a"},{"fixed":"15f0eb32f856016b6a3a04c8679b9a12eb18c203"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.2.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v3.2.0","v3.1.7","v3.1.5","v3.1.4","v3.1.3","v3.1.2","v3.1.1","v3.1.0","v3.1.0-rc12","v3.1.0-rc11","v3.1.0-rc10","v3.1.0-rc9","v3.1.0-rc8","v3.0.7","v3.1.0-rc7","v3.1.0-beta6","v3.1.0-beta5","v3.1.0-beta4","v3.1.0-alpha3","v3.1.0-alpha1","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61504.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}