Stored Cross-Site Scripting Vulnerability in Open Computer Use by e2b-dev
CVE-2026-108722

2.3LOW

Key Information:

Vendor

E2b-dev

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108722?

The Open Computer Use software contains a stored cross-site scripting vulnerability resulting from improper handling of HTML content in log files. Specifically, the function Logger.write_log_file in logging.py allows attackers to inject malicious scripts into the log.html file, which incurs risk when operators access this log. This issue arises when user-controlled content, such as web pages or command output files, is included without sufficient HTML escaping. Consequently, this could lead to unauthorized script execution and sensitive information exfiltration when users open compromised logs.

Affected Version(s)

open-computer-use 0 <= 610bac85d242b2fdf43fbe36bce2348658a2d4c9

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.