OVERVIEW Hayabusa versions before 3.8.0 contain a stored cross-site scripting (XSS) vulnerability in HTML report generation functionality. The vulnerability exists in the Computer field of JSON-exported logs, allowing threat actors to inject malicious JavaScript that executes when forensic examiners view the generated HTML reports. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.4 (Medium) with network-based attack vector and low attack complexity. While exploitation requires prior authentication and user interaction, the cross-site nature of the attack can affect multiple security domains. Potential impacts include information disclosure and limited code execution within the user's browser session during report analysis. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains on the inactive Hot List. The EPSS score of 0.00031 indicates significantly lower probability of exploitation compared to typical vulnerabilities, suggesting limited community attention and no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:yamato-security:hayabusa:*:*:*:*:*:*:*:* | ||
>= 0, <= 3.7.0CPE match | cpe:2.3:a:yamato-security:hayabusa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.