CVE-2026-34530 File Browser vulnerability

Dissecting CVE-2026-34530: Stored XSS via text/template Branding injection

For this blog, we’ll look at CVE-2026-34530: Stored Cross-Site Scripting via text/template branding injection and trace it back to the source code to understand exactly where and why the vulnerability exists. We have two keyword in the title: Stored Cross-Site Scripting text/template branding injection The blog assumes you at least have a basic understanding of Cross-Site Scripting. You may learn more about it at What is cross-site scripting (XSS)? We’ll come down to the second keyword: text/template branding injection ...

September 4, 2026 · 3 min · Spandan Pokhrel
CVE-2026-73613 File Browser vulnerability

Dissecting CVE-2026-73613: File Deletion via Symlink in TUS

For this blog, we’ll look at CVE-2026-73613: Out-of-scope file deletion via symlink-following delete in TUS upload-cache eviction and trace it back to the source code to understand exactly where the vulnerable behavior comes from and how it can lead to file deletion outside the intended directory. We have 3 keywords in the title: Out-of-scope file deletion symlink TUS upload-cache eviction 1. Out-of-scope file deletion This one is pretty simple. Consider the following scenario: ...

September 3, 2026 · 5 min · Spandan Pokhrel