#VU125397 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in FileBrowser - CVE-2026-34529
Published: April 8, 2026
FileBrowser
File Browser
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in EPUB file rendering when processing a crafted EPUB file. A remote user can upload a specially crafted EPUB file to execute arbitrary script in a victim's browser.
User interaction is required to open the crafted EPUB content.