Description
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Published: 2026-09-13
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via XSS
Action: Apply Patch
AI Analysis

Impact

Amundsen frontend releases through version 4.3.0 render table, dashboard, and feature descriptions using dangerouslySetInnerHTML without any HTML sanitization. The stored input fields are populated from the metadata service or Elasticsearch, allowing an attacker to place malicious markup such as an image tag with an onerror handler into a description. When a user views a search result that includes the injected markup, the browser executes the attacker‑supplied JavaScript in the context of the Amundsen application, granting the attacker the ability to run arbitrary code, steal session cookies, or perform other client‑side attacks.

Affected Systems

The vulnerability impacts the Amundsen Frontend component (amundsen-io/amundsen-frontend) for all deployments using version 4.3.0 or earlier. No other vendors or products are listed as affected.

Risk and Exploitability

8.3, indicating high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw by inserting malicious content into a description field via the metadata service or Elasticsearch, content is at risk of executing arbitrary JavaScript. Because the exploit path requires the attacker to insert data into the description field, it is likely that the vulnerability is exploitable in environments where the metadata service or Elasticsearch is accessible to the attacker and description inputs are not strictly controlled.

Generated by OpenCVE AI on September 15, 2026 at 16:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Amundsen frontend to a release newer than 4.3.0 where description rendering is sanitized and dangerouslySetInnerHTML is removed.
  • Configure a Content Security Policy that blocks inline scripts and disallows execution of potentially injected JavaScript event handlers.
  • Validate prevent HTML markup from being stored, for to the metadata service or Elasticsearch.

Generated by OpenCVE AI on September 15, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Amundsen-io
Amundsen-io amundsen-frontend
Vendors & Products Amundsen-io
Amundsen-io amundsen-frontend

Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Title Amundsen Frontend through 4.3.0 Stored XSS via Description
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Amundsen-io Amundsen-frontend
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:53.282Z

Reserved: 2026-09-13T10:14:58.070Z

Link: CVE-2026-90772

cve-icon Vulnrichment

Updated: 2026-09-14T17:31:47.610Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:01.780

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-90772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')