PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78337 Roskus CVE debrief

The CVE-2026-78337 record indicates an Unrestricted Upload of File with Dangerous Type vulnerability in Roskus Prospero Flow CRM before 5.15.13. An authenticated user with create and update company permissions can upload an SVG document containing an embedded script element to execute arbitrary JavaScript in the application origin. This vulnerability has a CVSS score of 4.8, indicating a MEDIUM severity level. Administrators and users of Roskus Prospero Flow CRM, especially those with create and update company permissions, should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-24T11:16:41.203Z and has not been modified since then.

Vendor
Roskus
Product
Prospero Flow CRM
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-24
Original CVE updated
2026-09-01
Advisory published
2026-08-24
Advisory updated
2026-09-01

Who should care

Administrators and users of Roskus Prospero Flow CRM, especially those with create and update company permissions, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and applying patches, restricting file uploads to safe types, and monitoring for suspicious activity. Security teams responsible for managing and securing instances of Roskus Prospero Flow CRM should prioritize this vulnerability due to its potential impact on application security and integrity. Additionally, operators and platform administrators should verify their current version and plan for updates or mitigations as needed. Vulnerability management processes should be engaged to ensure proper tracking and remediation of this issue within the organization. The CVE record indicates that the vulnerability has not been modified since its publication, suggesting that no additional information has been provided that would alter the initial assessment of risk and impact. Therefore, it is crucial for affected parties to act based on the current information available. The vulnerability's MEDIUM severity level should not be underestimated, as the ability to execute arbitrary JavaScript could lead to significant security breaches if exploited. Therefore, proactive measures are essential to prevent potential misuse. This situation underscores the importance of maintaining up-to-date software versions and implementing robust security controls to protect against such vulnerabilities. By taking these steps, organizations can reduce the risk associated with CVE-2026-78337 and enhance their overall security posture. In light of this vulnerability, it is advisable for organizations to conduct a thorough review of their current security practices and make necessary adjustments to address this and similar potential threats effectively. This includes ensuring that security patches are applied promptly, that file upload processes are properly secured, and that monitoring and logging mechanisms are in place to detect and respond to potential security incidents. By doing so, organizations can better protect their assets and minimize the risk of exploitation. The CVE

Technical summary

The vulnerability exists in the company logo upload feature of Roskus Prospero Flow CRM before version 5.15.13. An authenticated user with create and update company permissions can upload an SVG file containing an embedded script element, which can be used to execute arbitrary JavaScript in the application origin. The CVSS score for this vulnerability is 4.8, indicating a MEDIUM severity level. This issue is particularly concerning because it allows for the execution of arbitrary JavaScript, potentially leading to unauthorized actions within the application. The vulnerability was publicly disclosed on 2026-08-24T11:16:41.203Z.

Defensive priority

Authenticated users with create and update company permissions can execute arbitrary JavaScript via an SVG file upload vulnerability in Roskus Prospero Flow CRM before 5.15.13.

Recommended defensive actions

  • Inventory and verify the version of Roskus Prospero Flow CRM in use.
  • Restrict file uploads to only allow specific, safe file types.
  • Implement additional security controls, such as validating and sanitizing user-uploaded files.
  • Monitor for suspicious activity and implement logging and alerting for potential security incidents.
  • Apply the vendor-provided patch or upgrade to version 5.15.13 or later.

Evidence notes

The CVE-2026-78337 record indicates an Unrestricted Upload of File with Dangerous Type vulnerability in Roskus Prospero Flow CRM before 5.15.13. An authenticated user with create and update company permissions can upload an SVG document containing an embedded script element to execute arbitrary JavaScript. The CVSS score is 4.8, and the severity is MEDIUM.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78337 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78337

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78337 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78337

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Roskus/prospero-flow-crm/commit/aaa4fc76bf039d5011884b86b8f29ddd50d17b17

    4daa8cea-433a-44bd-9456-53b127fc289a

  • Source reference

    Unverified legacy reference

    URL: https://secur0.com/en/cna/cve-list/cve-2026-78337-unrestricted-upload-company-logo-svg-xss

    4daa8cea-433a-44bd-9456-53b127fc289a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.