Impact
The vulnerability is a stored XSS flaw introduced by the Logger.write_log_file function in the open‑computer‑use project, which writes transcript text to log.html without HTML escaping. An attacker who can inject content into sandbox files or web pages can place JavaScript that will run when an operator opens the log file, enabling the exfiltration of transcript data or execution of arbitrary scripts within the operator’s environment.
Affected Systems
The affected product is open‑computer‑use from e2b‑dev, specifically the code base that includes commit 610bac8. No other versions or products have been reported as vulnerable in the CVE data.
Risk and Exploitability
The CVSS score of 2.3 indicates low overall severity, and the EPSS score is not available, which suggests limited predictive exploitation data. The vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to supply sandbox content that includes malicious script, and the malicious code will only execute when a human operator opens the log.html file. Thus the exploitability is constrained to insider or social‑engineering scenarios where an operator is tricked into reviewing a compromised log. Nevertheless, the ability to capture session data remains a concern for environments that rely on open‑computer‑use for secure sandboxed operations.
OpenCVE Enrichment