CVE Feed

    Dashboard / CVE / CVE-2024-9526

    CVE-2024-9526

    There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d

    Published:Nov 18, 2024
    Last Modified:Jul 23, 2025
    EPS:Nov 18, 2024
    EPSS Score:0.00069
    CVSS Score:5.4

    Affected Products

    Vendor
    Kubeflow
    Product
    Kubeflow W Pipeline View
    Vendor
    Kubeflow
    Product
    Pipelines

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High