Stored Cross-Site Scripting Vulnerability in Open Computer Use by e2b-dev
CVE-2026-108722
2.3LOW
What is CVE-2026-108722?
The Open Computer Use software contains a stored cross-site scripting vulnerability resulting from improper handling of HTML content in log files. Specifically, the function Logger.write_log_file in logging.py allows attackers to inject malicious scripts into the log.html file, which incurs risk when operators access this log. This issue arises when user-controlled content, such as web pages or command output files, is included without sufficient HTML escaping. Consequently, this could lead to unauthorized script execution and sensitive information exfiltration when users open compromised logs.
Affected Version(s)
open-computer-use 0 <= 610bac85d242b2fdf43fbe36bce2348658a2d4c9
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
