CVE-2026-32722 - Vulnerability Analysis
LowCVSS: 3.6Last Updated: March 18, 2026
Memray - Stored XSS
Published: March 18, 2026Updated: March 18, 2026PoC Available
Overview
Memray < 1.19.2 contains a stored XSS caused by unescaped attacker-controlled command line arguments rendered in HTML reports, letting attackers execute JavaScript when victims open the report, exploit requires attacker control of command line arguments.
Severity & Score
Severity: Low
CVSS Score: 3.6
Impact
Attackers can execute arbitrary JavaScript in victim's browser when opening the report, potentially leading to session hijacking or data theft.
Mitigation
Update to version 1.19.2 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-32722
- Severity
- Low
- CVSS Score
- 3.6
- Type
- stored_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N