Medium severity4.2NVD Advisory· Published Oct 11, 2026
CVE-2026-108722
CVE-2026-108722
Description
open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.
Affected products
1- Range: through commit 610bac8
Patches
Vulnerability mechanics
References
4- github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/logging.pynvd
- github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/sandbox_agent.pynvd
- hackmd.io/@haind03/e2b-open-computer-use-html-log-injectionnvd
- www.vulncheck.com/advisories/open-computer-use-through-commit-610bac8-stored-xss-via-log-html-session-lognvd
News mentions
0No linked articles in our index yet.