{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aamundsenfrontend/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:amundsen:frontend:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-90772"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Amundsen frontend (\u003c= 4.3.0)"],"_cs_severities":["high"],"_cs_tags":["web-security","xss","injection"],"_cs_type":"advisory","_cs_vendors":["Amundsen"],"content_html":"\u003cp\u003eAmundsen frontend versions through 4.3.0 contain a Stored Cross-Site Scripting (XSS) vulnerability due to the improper use of React's dangerouslySetInnerHTML property. The application fails to sanitize table, dashboard, or feature descriptions rendered within ResourceListItem components. This allows an attacker who can influence the metadata ingested into Amundsen - typically via the metadata service or the underlying Elasticsearch index - to inject malicious HTML content. When a legitimate user views search results containing these compromised descriptions, the injected scripts (e.g., img elements with onerror handlers) execute within the context of the user's session. This could lead to credential theft, session hijacking, or unauthorized actions performed on behalf of the victim user within the Amundsen interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary JavaScript execution in the browser of any user who views search results containing malicious descriptions. This impacts all organizations using Amundsen frontend 4.3.0 or earlier, potentially exposing internal data lineage and business intelligence metadata to unauthorized manipulation or exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Amundsen frontend to a version beyond 4.3.0 that implements HTML sanitization for description fields.\u003c/li\u003e\n\u003cli\u003eAudit metadata sources (metadata service, Elasticsearch) to identify and remove existing malicious payload strings in table or dashboard descriptions.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) that restricts script execution to trusted domains to mitigate the impact of XSS, even if rendering logic remains flawed.\u003c/li\u003e\n\u003cli\u003eRestrict write access to the metadata service and the Elasticsearch backend to authorized service accounts only to prevent unauthorized injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T11:26:06Z","date_published":"2026-09-13T11:26:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-amundsen-xss/","summary":"Amundsen frontend versions through 4.3.0 allow Stored Cross-Site Scripting via unsanitized rendering of metadata descriptions, enabling arbitrary JavaScript execution in victim browsers.","title":"Stored XSS in Amundsen Frontend","url":"https://feed.craftedsignal.io/briefs/2026-09-amundsen-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:amundsen:frontend:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}