LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32722

CVE-2026-32722 - Vulnerability Analysis

LowCVSS: 3.6

Last Updated: March 18, 2026

Memray - Stored XSS

Published: March 18, 2026Updated: March 18, 2026PoC Available

Overview

Memray < 1.19.2 contains a stored XSS caused by unescaped attacker-controlled command line arguments rendered in HTML reports, letting attackers execute JavaScript when victims open the report, exploit requires attacker control of command line arguments.

Severity & Score

Severity: Low
CVSS Score: 3.6

Impact

Attackers can execute arbitrary JavaScript in victim's browser when opening the report, potentially leading to session hijacking or data theft.

Mitigation

Update to version 1.19.2 or later.

Details

CVE ID
CVE-2026-32722
Severity
Low
CVSS Score
3.6
Type
stored_xss
Status
new

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N