Stored cross-site scripting in the participant URL handling in AWS Ops
Wheel before PR #168 might allow an authenticated remote user to steal
session tokens and escalate to full administrative control of the
deployed instance via a crafted participant_url value containing a
dangerous URI scheme.
To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
References
Configurations
No configuration.
History
31 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
31 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-31 19:17
Updated : 2026-07-31 20:16
NVD link : CVE-2026-18481
Mitre link : CVE-2026-18481
CVE.ORG link : CVE-2026-18481
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
