Impact
OpenSearch Dashboards contains an input validation flaw in the Vega expression function implementation. The checkForFunctionProperty routine fails to recurse into arrays of objects, so a function property can be nested inside an array and bypass validation. An authenticated user with dashboard write permissions can save a crafted Vega visualization that includes arbitrary JavaScript. When other users load the visualization, the script runs in their browser context, potentially compromising their session data and allowing further malicious actions. The vulnerability falls under CWE‑79, a stored cross‑site scripting flaw.
Affected Systems
This flaw affects AWS Amazon OpenSearch Service and OpenSearch Dashboards from versions prior to 2.19.5 and 3.6.0. Users running older releases should verify their current version and upgrade as appropriate.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have dashboard write permissions, but once authenticated they can embed malicious code that is persisted in the dashboard for future users to load. The exploit requires only the ability to create or edit a Vega visualization, a common capability for many dashboard users.
OpenCVE Enrichment