Executive brief
Roxy-WI, a management interface for web servers like HAProxy and Nginx, contains a security flaw in its log viewing feature. An attacker can send a specially crafted web request to any server managed by Roxy-WI, which places malicious code into the server's access logs. When an administrator later views these logs through the Roxy-WI dashboard, the malicious code executes in their browser, potentially allowing the attacker to hijack the administrator's session or modify system settings.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Roxy-WI versions 8.2.6.4 and prior. The functions 'wrap_line' and 'highlight_word' in 'app/modules/common/common.py' generate raw HTML via string concatenation without performing output encoding or sanitization. Furthermore, the frontend uses jQuery's '.html()' and '.append()' methods to inject this unescaped data into the DOM. An unauthenticated attacker can trigger this by sending an HTTP request with a malicious payload (e.g., in the User-Agent header) to a managed HAProxy or Nginx instance. When an administrator views the logs via the Roxy-WI web interface, the payload executes. As of publication, no official patch is available; users are advised to manually implement HTML escaping using libraries like 'markupsafe'.
Affected products
- Roxy-WI Roxy-WI <= 8.2.6.4
Timeline
- 2026-05-15: advisory: GitHub Security Advisory published
- 2026-06-10: disclosed: CVE published to NVD