CVE-2026-72570: Cube-Root Directory-Serve
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.
Affected products
- Cube-Root Directory-Serve: up to and including 1.3.7
Published 2026-08-10. Last modified 2026-09-03.