๐Ÿ” CVE Alert

CVE-2026-90772

HIGH 7.6

Amundsen Frontend through 4.3.0 Stored XSS via Description

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.

CWE CWE-79
Vendor amundsen-io
Product amundsen-frontend
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for amundsen-io amundsen-frontend

Be the first to know when new high vulnerabilities affecting amundsen-io amundsen-frontend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

amundsen-io / amundsen-frontend
0 โ‰ค 4.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/amundsen-io/amundsen/issues/2362 github.com: https://github.com/amundsen-io/amundsen github.com: https://github.com/amundsen-io/amundsen/blob/frontend-4.3.0/frontend/amundsen_application/static/js/components/ResourceListItem/TableListItem/index.tsx vulncheck.com: https://www.vulncheck.com/advisories/amundsen-frontend-through-4.3.0-stored-xss-via-description

Credits

๐Ÿ” George Chen