Description
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
Published: 2026-07-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic cross‑site scripting flaw that allows a remote attacker to inject and execute arbitrary scripts during web page generation. This weakness, identified as CWE‑79, can compromise the confidentiality, integrity, and availability of the affected system by permitting attackers to run arbitrary code on the host or context.

Affected Systems

IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are subject to this input validation flaw identified as CWE‑79.

Risk and Exploitability

With a CVSS score of 9.3 the flaw poses a critical risk, yet the EPSS score of less than 1% indicates that exploitation probability is currently very low. The vulnerability is not listed in CISA KEV, but the advisory urges urgent patching. Based on the description, it is inferred that the attacker must be able to supply crafted input to the vulnerable page rendering process.

Generated by OpenCVE AI on July 30, 2026 at 23:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected productFixed in releaseInstructionsIBM Engineering AI Hub v1.0.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.1.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.2.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading


OpenCVE Recommended Actions

  • Update IBM Engineering AI Hub to the latest supported release (v1.0.01.3.0, v1.1.01.3.0, or v1.2.01.3.0) following the official upgrade guidance.
  • Apply input validation and HTML encoding to all data rendered in web pages to prevent script injection.
  • Monitor application logs for unusual script execution patterns and review access controls to restrict untrusted input sources.

Generated by OpenCVE AI on July 30, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
Title Multiple Vulnerabilities in IBM Engineering AI hub.
First Time appeared Ibm
Ibm engineering Ai Hub
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:engineering_ai_hub:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.2.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Ai Hub
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Engineering Ai Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T15:16:23.830Z

Reserved: 2026-07-08T16:07:31.099Z

Link: CVE-2026-15091

cve-icon Vulnrichment

Updated: 2026-07-20T15:16:17.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')