HIGH

CVE-2026-90772

2026-09-13 CVSS v3.1
CVSS
7.6

Description

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.21%
Probability of exploitation in next 30 days
11.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE