๐Ÿ” CVE Alert

CVE-2026-11436

MEDIUM 4.3

Mage AI Sign-in Flow index.tsx useMutation cross site scripting

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-79 CWE-94
Vendor n/a
Product mage ai
Published Jun 6, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for n/a mage ai

Be the first to know when new medium vulnerabilities affecting n/a mage ai are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Mage AI
0.9.0 0.9.1 0.9.2 0.9.3 0.9.4 0.9.5 0.9.6 0.9.7 0.9.8 0.9.9 0.9.10 0.9.11 0.9.12 0.9.13 0.9.14 0.9.15 0.9.16 0.9.17 0.9.18 0.9.19 0.9.20 0.9.21 0.9.22 0.9.23 0.9.24 0.9.25 0.9.26 0.9.27 0.9.28 0.9.29 0.9.30 0.9.31 0.9.32 0.9.33 0.9.34 0.9.35 0.9.36 0.9.37 0.9.38 0.9.39 0.9.40 0.9.41 0.9.42 0.9.43 0.9.44 0.9.45 0.9.46 0.9.47 0.9.48 0.9.49 0.9.50 0.9.51 0.9.52 0.9.53 0.9.54 0.9.55 0.9.56 0.9.57 0.9.58 0.9.59 0.9.60 0.9.61 0.9.62 0.9.63 0.9.64 0.9.65 0.9.66 0.9.67 0.9.68 0.9.69 0.9.70 0.9.71 0.9.72 0.9.73 0.9.74 0.9.75 0.9.76 0.9.77 0.9.78 0.9.79

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/369016 vuldb.com: https://vuldb.com/vuln/369016/cti vuldb.com: https://vuldb.com/cve/CVE-2026-11436 vuldb.com: https://vuldb.com/submit/822710 gist.github.com: https://gist.github.com/TrebledJ/8af312cf797391ef7b50b94bb244333a

Credits

๐Ÿ” trebledj (VulDB User) VulDB CNA Team