Security Advisory

CVE-2026-90772

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-13 10:45:43
Last updated 2026-09-14 17:31:51
Assigner VulnCheck
CVSS score 8.3
State PUBLISHED

Description

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.