{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fiftyone/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-80426"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FiftyOne"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Voxel51"],"content_html":"\u003cp\u003eVoxel51's FiftyOne platform contains a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-80426. The vulnerability exists within the 'FieldLabelAndInfo' component, which renders dataset field descriptions using React's 'dangerouslySetInnerHTML' without prior sanitization or escaping. Because these descriptions are stored as part of the dataset schema, the payload persists across database entries and travels with exported or published datasets.\u003c/p\u003e\n\u003cp\u003eWhen a victim opens a malicious dataset, the XSS payload executes within the context of the FiftyOne application origin. This origin is shared with the unauthenticated FiftyOne server media route. An attacker can leverage this execution context to read local files on the server or interact with sensitive dataset and operator endpoints, potentially resulting in unauthorized data access or local file disclosure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious dataset with a crafted XSS payload injected into a field's description string.\u003c/li\u003e\n\u003cli\u003eThe malicious dataset is exported or distributed to a victim.\u003c/li\u003e\n\u003cli\u003eThe victim imports the malicious dataset into their instance of FiftyOne.\u003c/li\u003e\n\u003cli\u003eThe victim navigates to the UI component that displays the malicious dataset's field information.\u003c/li\u003e\n\u003cli\u003eThe 'FieldLabelAndInfo' component renders the description via 'dangerouslySetInnerHTML', triggering the malicious script.\u003c/li\u003e\n\u003cli\u003eThe script executes within the FiftyOne origin and makes requests to the unauthenticated media route.\u003c/li\u003e\n\u003cli\u003eThe script reads arbitrary local files or interacts with internal operator endpoints as the authenticated user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the FiftyOne browser context. This grants an attacker the ability to bypass existing security controls to access sensitive dataset information, trigger operator endpoints, and potentially read local files accessible to the FiftyOne server, impacting data integrity and confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FiftyOne to a patched version that sanitizes field descriptions before rendering.\u003c/li\u003e\n\u003cli\u003eAvoid importing or opening datasets from untrusted or unverified third-party sources until the patch is applied.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the FiftyOne server to trusted internal users to mitigate the impact of the unauthenticated media route.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:21:55Z","date_published":"2026-08-26T16:21:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fiftyone-xss/","summary":"FiftyOne versions are vulnerable to stored cross-site scripting (XSS) due to improper sanitization of dataset field descriptions, allowing attackers to execute arbitrary scripts in the application origin.","title":"Stored XSS in FiftyOne via Dataset Field Descriptions","url":"https://feed.craftedsignal.io/briefs/2026-08-fiftyone-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - FiftyOne","version":"https://jsonfeed.org/version/1.1"}