HIGHCVSS 7.6Vulnerability

CVE-2026-90772

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
7.6
retrieved_at
2026-09-25T21:30:45+00:00
score
7.6
last_source
NVD
cve_id
CVE-2026-90772
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
signal_observed_at
2026-09-25T21:30:45+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
published_at
2026-09-13T11:17:01.780
last_modified
2026-09-24T20:43:32.537

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90772 (CVSS 7.6) — Ninja Signal Threat Intelligence | Ninja Signal