Impact
The vulnerability is a classic cross‑site scripting flaw that allows a remote attacker to inject and execute arbitrary scripts during web page generation. This weakness, identified as CWE‑79, can compromise the confidentiality, integrity, and availability of the affected system by permitting attackers to run arbitrary code on the host or context.
Affected Systems
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are subject to this input validation flaw identified as CWE‑79.
Risk and Exploitability
With a CVSS score of 9.3 the flaw poses a critical risk, yet the EPSS score of less than 1% indicates that exploitation probability is currently very low. The vulnerability is not listed in CISA KEV, but the advisory urges urgent patching. Based on the description, it is inferred that the attacker must be able to supply crafted input to the vulnerable page rendering process.
OpenCVE Enrichment