Executive brief
RustFS Console is a web-based management interface for the RustFS distributed file system. A security flaw allows attackers to upload malicious files disguised as PDFs that, when viewed by an administrator, execute unauthorized code in their browser. This can lead to the theft of administrative credentials (access keys and session tokens), allowing an attacker to take full control of the file system, delete data, or access sensitive files.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx. The vulnerability is a regression of CVE-2026-27822 caused by relying on file extensions (e.g., .pdf) rather than Content-Type headers to determine preview logic. An attacker with low privileges can upload an HTML file renamed with a .pdf extension; when an administrator previews this file, the console renders it as HTML instead of a sandboxed object. This allows the attacker to execute arbitrary JavaScript in the context of the management console, enabling the theft of AccessKeyId, SecretAccessKey, and SessionToken values from localStorage. The issue is fixed in version 0.1.10 by restricting PDF previews to the application/pdf content type.
Affected products
- RustFS Console >= 0.1.7, < 0.1.10
Timeline
- 2026-03-09: other: Regression introduced in commit 4b40353d
- 2026-06-26: patched: Version 0.1.10 released
- 2026-07-15: disclosed: CVE-2026-62378 published