Unrated severityNVD Advisory· Published Mar 4, 2026· Updated Mar 5, 2026
OnDemand susceptible to malicious input when navigating to a directory.
CVE-2026-26002
Description
Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible.
Affected products
3- Range: <4.0.9 or <4.1.3
- OSC/ondemandv5Range: < 4.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/OSC/ondemand/commit/23cb167222886fdd8415277ca5c1215f4c32629cmitrex_refsource_MISC
- github.com/OSC/ondemand/commit/37f0ae4efb222e9c0af250feae860a720427df16mitrex_refsource_MISC
- github.com/OSC/ondemand/security/advisories/GHSA-f83q-mhrr-3cr2mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.