Hunter[verified]@HunterMappingPoC
The tweet alerts to a critical XSS vulnerability in RustFS that could lead to admin account takeover, provides a PoC link, and highlights widespread exposure but does not report active exploitation or a patch.
ThreatSynop[verified]@ThreatSynopDisclosure
A stored XSS flaw in RustFS Console lets attackers upload a .pdf with HTML to execute JavaScript, steal S3 credentials from localStorage, and take over admin accounts; upgrading to 1.0.0-alpha.83 and applying CSP mitigations resolves the issue.
VulnTracker[verified]@vuln_trackerGeneral
The message merely points to a vulnerability tracker page for CVE-2026-27822, providing no additional technical or exploitation details.
VulnTracker[verified]@vuln_trackerGeneral
Tweet directs readers to a vulnerability tracker page for CVE-2026-27822.
CVETodo[verified]@CveTodoDisclosure
A critical stored XSS vulnerability (CVE‑2026‑27822) affects RustFS versions before 1.0.0‑alpha.83, impacting the management console.
Gray Hats@the_yellow_fallPatch
RustFS has released a patch (1.0.0‑alpha.83) for CVE‑2026‑27822, a critical XSS flaw that could let attackers steal S3 credentials through malicious file previews; users are urged to update promptly.
CCB Alert@CCBalertDisclosure
A critical XSS vulnerability (CVE-2026-27822) in RustFS Console is disclosed with a CVSS score of 10, potentially allowing credential theft and admin takeover.
Autumn Good@autumn_good_35Disclosure
The advisory announces a critical stored XSS vulnerability in rustfs’s PDF preview modal that can steal admin credentials, but it does not provide a PoC, exploit code, or patch details.