← Πίσω στην αναζήτηση CVE

CVE-2026-80426

FiftyOne

Περιγραφή

FiftyOne renders a dataset field-s description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React-s dangerouslySetInnerHTML, and no layer between storage and render escapes or sanitises it; the neighbouring info values in the same component are rendered as React children and are escaped, so the description is the only raw path. A description is free-form text held in the dataset schema, so it persists in the database and travels with an exported or published dataset. Opening a dataset obtained from another party and hovering the field runs the stored markup in the application-s origin. That origin is shared with the FiftyOne server, whose media route returns the contents of a caller-named absolute path and which is unauthenticated in the open-source server, so the injected script can read local files and reach the dataset and operator endpoints as the viewing user.

CVSS 7.1EPSS 0.231%Κίνδυνος 0.72
Προβολή πηγής
Δημοσίευση
2026-08-26 16:16:44
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-26 19:17:19
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N