Description

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.

INFO

Published Date :

2026-01-08T18:22:05.661Z

Last Modified :

2026-01-08T18:38:12.920Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-22257 vulnerability.

Vendors Products
Salvo-rs
  • Salvo
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact