๐Ÿ” CVE Alert

CVE-2026-26002

UNKNOWN 0.0

OnDemand susceptible to malicious input when navigating to a directory.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible.

CWE CWE-74
Vendor osc
Product ondemand
Published Mar 4, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for osc ondemand

Be the first to know when new unknown vulnerabilities affecting osc ondemand are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OSC / ondemand
< 4.0.9 >= 4.1.0, < 4.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OSC/ondemand/security/advisories/GHSA-f83q-mhrr-3cr2 github.com: https://github.com/OSC/ondemand/commit/23cb167222886fdd8415277ca5c1215f4c32629c github.com: https://github.com/OSC/ondemand/commit/37f0ae4efb222e9c0af250feae860a720427df16