Medium severity5.4NVD Advisory· Published Nov 9, 2023· Updated Jun 17, 2026
CVE-2023-45885
CVE-2023-45885
Description
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openmctnpm | <= 3.1.0 | — |
Affected products
3- NASA/Open MCTdescription
Patches
Vulnerability mechanics
References
5- www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4fnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-v8fc-qxvj-f3mgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-45885ghsaADVISORY
- github.com/nasa/openmct/pull/7148ghsaWEB
- github.com/nasa/openmct/pull/7148/commits/4e95e12559c9c5364269ff366a59768573baacb4ghsaWEB
News mentions
0No linked articles in our index yet.