Impact
The vulnerability is a stored cross‑site scripting flaw in the RustFS Console’s preview modal and PDF viewer components. By uploading a specially crafted PDF that contains embedded HTML, an attacker can execute arbitrary script within the management console. This allows the attacker to read privileged data such as the administrator AccessKeyId, SecretAccessKey, and SessionToken, and ultimately to take over the administrative account.
Affected Systems
Affected is the RustFS Console for the RustFS distributed file system. Versions 0.1.7 through 0.1.9 inclusive contain the flaw. The issue is fixed in release 0.1.10.
Risk and Exploitability
TheSS score of 9 indicates high severity, and the EPSS score of less than 1% suggests low but still possible exploitation likelihood at this time. The vulnerability is not listed in CISA KEV. The flaw requires uploading a malicious PDF through the preview modal, a capability normally restricted to authenticated users. An attacker who can gain access to the console or a user with privilege to upload can deliver the payload and immediately gain administrative control. Thus the attack vector is inferred to be web‑based, relying on authenticated upload access.
OpenCVE Enrichment