HIGH
CVE-2026-90772
CVSS
7.6
Description
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.21%
Probability of exploitation in next 30 days
11.4th percentile
References
https://github.com/amundsen-io/amundsen
https://github.com/amundsen-io/amundsen/blob/frontend-4.3.0/frontend/amundsen_application/static/js/components/ResourceListItem/TableListItem/index.tsx
https://github.com/amundsen-io/amundsen/issues/2362
https://www.vulncheck.com/advisories/amundsen-frontend-through-4.3.0-stored-xss-via-description
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.