CVE-2026-18481

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Configurations

No configuration.

History

31 Jul 2026, 20:16

Type Values Removed Values Added
References
  • () https://github.com/aws/aws-ops-wheel/pull/168 -
  • () https://github.com/aws/aws-ops-wheel/security/advisories/GHSA-6rr8-cf9x-pj23 -

31 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 19:17

Updated : 2026-07-31 20:16


NVD link : CVE-2026-18481

Mitre link : CVE-2026-18481

CVE.ORG link : CVE-2026-18481


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')