PT-2026-40947 · Unknown · Open Ondemand

·

CVE-2026-44371

·

Published

2026-05-14

·

Updated

2026-05-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Open OnDemand versions prior to 4.0.11 Open OnDemand versions prior to 4.1.5 Open OnDemand versions prior to 4.2.2
Description Specially crafted filenames can lead to the execution of arbitrary JavaScript within the file browser of this high-performance computing portal.
Recommendations Update to version 4.0.11. Update to version 4.1.5. Update to version 4.2.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44371
GHSA-XCV4-M435-M33H

Affected Products

Open Ondemand