CVE Watchtower

← Back to CVE List

CVE-2026-90772NVD

Description

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.
Severity Level
HIGH (7.6)
Published Date
13/09/2026
Last Modified
13/09/2026
Exploitation Status
????
EPSS Score
0.21% (percentile 11.4%)

CVSS Base Metrics

CVSS v3 (3.1)
HIGH 7.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
CVSS v4 (4.0)
HIGH 8.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Weaknesses (CWE)

CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected & Patched Versions

ProductAffected VersionsPatched Version
amundsen-io amundsen-frontend0 - <= 4.3.0N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.