{"apiVersion":"1.0","identifier":"CVE-2026-80426","description":"FiftyOne renders a dataset field-s description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React-s dangerouslySetInnerHTML, and no layer between storage and render escapes or sanitises it; the neighbouring info values in the same component are rendered as React children and are escaped, so the description is the only raw path. A description is free-form text held in the dataset schema, so it persists in the database and travels with an exported or published dataset. Opening a dataset obtained from another party and hovering the field runs the stored markup in the application-s origin. That origin is shared with the FiftyOne server, whose media route returns the contents of a caller-named absolute path and which is unauthenticated in the open-source server, so the injected script can read local files and reach the dataset and operator endpoints as the viewing user.","publishedAt":"2026-08-26T16:16:44","lastModifiedAt":"2026-08-26T19:17:19","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80426","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","epssProbability":0.00231,"riskScore":0.72,"affectedProduct":"FiftyOne","affectedVersions":"unknown","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80426","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80426","en":"https://www.redsauce.net/en/cves/CVE-2026-80426","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80426","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80426","de":"https://www.redsauce.net/de/cves/CVE-2026-80426","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80426","el":"https://www.redsauce.net/el/cves/CVE-2026-80426"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80426"}}