VYPR

OpenSearch Dashboards

by Opensearch Project

Source repositories

CVEs (4)

  • CVE-2026-18420HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype…

  • CVE-2026-84942HigSep 8, 2026
    risk 0.50cvss 8.7epss 0.01

    Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega…

  • CVE-2026-75897HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

  • CVE-2024-43794MedAug 23, 2024
    risk 0.33cvss 6.1epss 0.00

    OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters.…