PT-2026-31475 · Openstatushq · Openstatus

·

CVE-2026-5808

·

Published

2026-04-08

·

Updated

2026-04-08

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions openstatusHQ openstatus versions prior to 43d9b2b9ef8ae1a98f9bdc8a9f8a6d6a3dfaa2dfb
Description A remote cross-site scripting issue exists within the Onboarding Endpoint component in the file apps/dashboard/src/app/(dashboard)/onboarding/client.tsx. The flaw allows for the manipulation of the callbackURL argument to execute malicious scripts.
Recommendations Apply patch 43d9b2b9ef8ae1a98f9bdc8a9f8a6d6a3dfaa2dfb to resolve the issue.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5808

Affected Products

Openstatus