CVE-2024-9526

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d
References
Link Resource
https://github.com/kubeflow/pipelines/pull/10315 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:kubeflow:pipelines:*:*:*:*:*:*:*:*
First Time Kubeflow
Kubeflow pipelines
References () https://github.com/kubeflow/pipelines/pull/10315 - () https://github.com/kubeflow/pipelines/pull/10315 - Issue Tracking, Patch

Information

Published : 2024-11-18 14:15

Updated : 2025-07-23 19:42


NVD link : CVE-2024-9526

Mitre link : CVE-2024-9526

CVE.ORG link : CVE-2024-9526


JSON object : View

Products Affected

kubeflow

  • pipelines
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')