CVE-2026-72570: Cube-Root Directory-Serve

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.

Affected products

  • Cube-Root Directory-Serve: up to and including 1.3.7

Published 2026-08-10. Last modified 2026-09-03.