
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32722 is a stored Cross-Site Scripting (XSS) vulnerability in Bloomberg Memray, a memory profiler for Python, affecting all versions prior to 1.19.2. The flaw allows an attacker who can influence the script name or command-line arguments of a profiled program to inject arbitrary HTML/JavaScript into Memray-generated HTML reports (both flamegraph and table reports, with or without --no-web). The vulnerability was disclosed on March 13, 2026, and published to the GitHub Advisory Database on March 16, 2026. The CVSS v3.1 base score is 6.1 (Medium) per NVD, though the vendor's own advisory scores it 3.6 (Low) using a local attack vector (GitHub Advisory, Memray Advisory).
The root cause is a missing HTML escaping step in Memray's Jinja2 templating layer (CWE-79). Memray uses Jinja to embed the profiled process's command-line arguments into generated HTML reports via the {{ metadata.command_line }} template variable, but failed to apply the |e (escape) filter, allowing raw HTML to be written directly into the report. The fix, applied in commit ba6e4e2, changes the template to {{ metadata.command_line|e }} to properly escape the output (Patch Commit). Exploitation requires the attacker to control the script filename or command-line arguments of a process being profiled — this is particularly relevant with memray attach, where the user generating the report may differ from the user who originally launched the process (Memray Advisory). A public PoC demonstrates the attack using a maliciously named file: touch '<img src=x onerror=alert(1)>' followed by python -m memray run and python -m memray flamegraph (GitHub Advisory).
When a victim opens a Memray-generated HTML report containing injected JavaScript, the script executes in the context of the report within their browser, enabling theft of data visible in the report (e.g., memory profiling data, process metadata) and potential session-level actions within that context. The confidentiality impact is low and availability is unaffected; there is no direct integrity impact on the host system. The scope change (S:C) reflects that the injected script executes in the browser's security context rather than the application itself, potentially affecting data accessible to the victim's browser session (Memray Advisory, GitHub Advisory).
Public proof-of-concept exploit code is available on GitHub, with concrete reproduction steps and working payloads (PoC Repository, Memray Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018–0.022%, placing it in the 6th percentile for exploitation likelihood within 30 days (GitHub Advisory). The reporter credited with discovery is 0xmrma.
touch '<img src=x onerror=alert(document.cookie)>'python -m memray run -o poc.bin '<img src=x onerror=alert(document.cookie)>'python -m memray flamegraph -o poc.html poc.binpoc.html file to a victim user (e.g., via a shared filesystem, CI artifact, or email).poc.html in a browser, the unescaped payload in the Command line: field executes as JavaScript, achieving the attacker's objective (e.g., data exfiltration, session hijacking within the report context) (Memray Advisory, PoC Repository).<script>, <img src=x onerror=...>, or similar tags) in directories used for Memray profiling..html report files containing unescaped HTML tags within the Command line: section of the report body.memray run or memray attach invocations with suspicious script names or arguments containing angle brackets or JavaScript event handlers.Upgrade Bloomberg Memray to version 1.19.2 or later, which applies proper HTML escaping (|e filter) to command-line metadata in Jinja2 templates (Memray Release, Patch Commit). As a workaround prior to upgrading, avoid using memray attach on untrusted processes or processes whose command-line arguments may be attacker-controlled (Memray Advisory). Additionally, treat Memray-generated HTML reports as potentially untrusted artifacts and avoid opening reports generated from untrusted or externally-controlled processes in a browser until the upgrade is applied.
Red Hat tracked the vulnerability via Bugzilla (Bug 2448899) and published a corresponding CVE advisory, indicating awareness within the enterprise Linux ecosystem (Red Hat Bugzilla). The vulnerability was reported by security researcher 0xmrma, who also published a PoC repository shortly after disclosure (PoC Repository). No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability tracking.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."