High severity7.6NVD Advisory· Published Sep 13, 2026
CVE-2026-90772
CVE-2026-90772
Description
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=4.3.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.