{"id":"CVE-2024-9526","summary":"Stored XSS in Kubeflow Pipeline View","details":"There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d","aliases":["GO-2024-3278"],"modified":"2026-09-30T03:48:01.243487558Z","published":"2024-11-18T13:30:21.818Z","related":["openSUSE-SU-2024:14513-1"],"database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9526.json","cna_assigner":"Google"},"references":[{"type":"WEB","url":"https://github.com/kubeflow"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9526.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-9526"},{"type":"FIX","url":"https://github.com/kubeflow/pipelines/pull/10315"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kubeflow","events":[{"introduced":"0"},{"fixed":"930c35f1c543998e60e8d648ce93185c9b5dbe8d"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9526.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/S:P/AU:Y/R:U/V:D/RE:L/U:Green"}]}