๐Ÿ” CVE Alert

CVE-2026-44371

UNKNOWN 0.0

Open OnDemand: Specially crafted filenames can execute javascript in the file browser

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

CWE CWE-79
Vendor osc
Product ondemand
Published May 14, 2026
Last Updated May 14, 2026
Stay Ahead of the Next One

Get instant alerts for osc ondemand

Be the first to know when new unknown vulnerabilities affecting osc ondemand are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OSC / ondemand
< 4.0.11 >= 4.1.0, < 4.1.5 >= 4.2.0, < 4.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OSC/ondemand/security/advisories/GHSA-xcv4-m435-m33h