Vulnerability Description
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the management console and exposure of administrator AccessKeyId, SecretAccessKey, and SessionToken values. This is caused by a regression of CVE-2026-27822. This vulnerability is fixed in 0.1.10.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/rustfs/console/commit/49630dc140e6818aaee8879ade038a129838a2f
- https://github.com/rustfs/console/releases/tag/v0.1.10
- https://github.com/rustfs/rustfs/security/advisories/GHSA-7gcx-wg4x-q9x6
- https://github.com/rustfs/rustfs/security/advisories/GHSA-7gcx-wg4x-q9x6
FAQ
What is CVE-2026-62378?
CVE-2026-62378 is a vulnerability with a CVSS score of 9.0 (CRITICAL). RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx ...
How severe is CVE-2026-62378?
CVE-2026-62378 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-62378?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.