Medium severity5.4NVD Advisory· Published Nov 18, 2024· Updated Jun 17, 2026
CVE-2024-9526
CVE-2024-9526
Description
There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coordsRange: < 0.0.20241119T173509-1.1
- Kubeflow/Kubeflow Pipeline Viewv5Range: 0
Patches
Vulnerability mechanics
References
1- github.com/kubeflow/pipelines/pull/10315nvdIssue TrackingPatch
News mentions
0No linked articles in our index yet.