A vulnerability classified as problematic was found in cube-root directory-serve up to 1.3.7. Affected is an unknown function of the file lib/helper/html.js of the component Filename Handler. The manipulation results in cross site scripting.

This vulnerability was named CVE-2026-72570. The attack may be performed from remote. There is no available exploit.