Description
open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) that embeds malicious scripts into log.html, potentially executing code when operators view the log
Action: Apply Fix
AI Analysis

Impact

The vulnerability is a stored XSS flaw introduced by the Logger.write_log_file function in the open‑computer‑use project, which writes transcript text to log.html without HTML escaping. An attacker who can inject content into sandbox files or web pages can place JavaScript that will run when an operator opens the log file, enabling the exfiltration of transcript data or execution of arbitrary scripts within the operator’s environment.

Affected Systems

The affected product is open‑computer‑use from e2b‑dev, specifically the code base that includes commit 610bac8. No other versions or products have been reported as vulnerable in the CVE data.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity, and the EPSS score is not available, which suggests limited predictive exploitation data. The vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to supply sandbox content that includes malicious script, and the malicious code will only execute when a human operator opens the log.html file. Thus the exploitability is constrained to insider or social‑engineering scenarios where an operator is tricked into reviewing a compromised log. Nevertheless, the ability to capture session data remains a concern for environments that rely on open‑computer‑use for secure sandboxed operations.

Generated by OpenCVE AI on October 11, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest release of open‑computer‑use that includes the commit that patches the logging issue
  • Ensure that all data written to log.html is properly HTML‑escaped and that no untrusted input is included without sanitization
  • Restrict or validate sandbox content so that malicious JavaScript cannot be injected into the logging module or the run_command output

Generated by OpenCVE AI on October 11, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.
Title open-computer-use through commit 610bac8 Stored XSS via log.html Session Log
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:32.616Z

Reserved: 2026-10-11T01:52:30.972Z

Link: CVE-2026-108722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:15.673

Modified: 2026-10-11T13:17:15.673

Link: CVE-2026-108722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')