Sceawere

Vulnerability Detail

CVE-2026-108722UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in open-computer-use

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
4h ago
Vendor
e2b-dev
Product
open-computer-use
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-10-11T13:17:15.673Z",
  "pubdate": "2026-10-11T13:17:15.673Z",
  "executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists within the open-computer-use project, specifically affecting the logging mechanism. The vulnerability resides in the Logger.write_log_file function, where transcript data is persisted to log.html without adequate HTML encoding or sanitization.\nThis flaw allows an attacker who controls the sandbox environment—such as a malicious web page visited by the automated agent or an attacker-controlled file processed during run_command operations—to inject arbitrary JavaScript payloads into the log files. When an operator or administrator views the log file, the browser interprets the injected script as legitimate content, executing it within the context of the user's session.\nThe impact includes potential exfiltration of sensitive transcript contents, session hijacking, or unauthorized actions performed on behalf of the operator. Because the logs are designed for audit and review, this vector facilitates the compromise of security personnel or developers tasked with monitoring the agent's activity. The vulnerability affects all versions up to and including commit 610bac8.",
  "technicalDetails": "The vulnerability is a classic stored XSS flaw originating from improper neutralization of input during the generation of the log file. The affected component is the Logger.write_log_file method defined in os_computer_use/logging.py. In this implementation, the system captures transcript data—which includes outputs from sandboxed commands and web page contents—and appends it directly to a static log.html file.\nThe root cause is the absence of context-aware output encoding. When the system serializes the transcript into the HTML log, it fails to escape characters with special meaning in HTML (e.g., <, >, &, \", '). Consequently, if a sandboxed command produces an output string containing a <script> tag or an HTML attribute-based event handler (such as onload or onerror), that content is written verbatim into the log file.\nThe attack flow proceeds as follows: 1) An attacker gains control over content processed by the open-computer-use sandbox. This could be achieved by influencing the agent to navigate to a malicious URL or by placing a crafted file on the filesystem that the agent subsequently reads or executes via run_command. 2) The agent, performing its task, captures the attacker-controlled content as part of its transcript log. 3) The Logger.write_log_file function writes this content directly into the log.html file without any sanitization or escaping. 4) The victim (an operator or administrator) opens log.html in a web browser to review the agent's actions. 5) The browser encounters the injected script tags and executes the payload within the victim's local or web-based session. 6) The script executes with the privileges of the victim, allowing for the exfiltration of the entire transcript—which may contain sensitive environment variables, credentials, or proprietary information—to an attacker-controlled server via outbound network requests or DOM-based data leakage.\nThis vulnerability does not require authentication or specific privilege levels for the initial injection, as it relies on the agent's interaction with untrusted sandbox content. The exploit is successful as long as the agent is tricked into processing malicious output, and the resulting log file is later rendered by a browser. The post-exploitation impact includes persistent monitoring, credential theft, and potential lateral movement if the operator's browser session provides access to internal administrative interfaces."
}
CVE-2026-108722: Stored XSS in open-computer-use (MEDIUM Severity, CVSS: 4.2) | Sceawere