fig. 01 — GHSA-m8fw-534v-xm85, the advisory selected below
// advisories
GHSA-m8fw-534v-xm85
HIGH
Versions of cloudcmd before 9.1.6 are vulnerable to cross-site scripting (XSS) when listing files in a directory. The attacker must control the name of a file for this vulnerability to be exploitable.