CVE-2026-13083
EUVD-2026-3959626.06.2026, 00:16
A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | pen_drive | 𝑥 < 1.0.0-2 |
𝑥
= Vulnerable software versions