CVE-2026-108722
Received Received - Intake

Stored XSS in open-computer-use Logger

Vulnerability report for CVE-2026-108722, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
e2b-dev open-computer-use 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in the open-computer-use tool. It occurs in the Logger.write_log_file function in os_computer_use/logging.py, where transcript text is written to log.html without proper HTML escaping. Attackers can inject malicious scripts into sandbox content, such as web pages or files, which execute when operators open the log file. This allows attackers to exfiltrate transcript contents.

Detection Guidance

Check log.html files generated by open-computer-use for suspicious script tags or unescaped HTML content. Inspect Logger.write_log_file in os_computer_use/logging.py for improper HTML escaping of transcript text.

Impact Analysis

If you use open-computer-use, attackers could gain access to sensitive data in your logs, such as transcript contents, by injecting malicious scripts. This could lead to data breaches or unauthorized access to your system's interactions.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by exposing sensitive data in logs. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. A breach could result in legal penalties or loss of trust.

Mitigation Strategies

Update to a patched version of open-computer-use where Logger.write_log_file properly escapes HTML in log.html. If unavailable, manually escape HTML in transcript text before writing to logs or disable logging of untrusted content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108722. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart