Stored cross-site scripting in the participant URL handling in AWS Ops
Wheel before PR #168 might allow an authenticated remote user to steal
session tokens and escalate to full administrative control of the
deployed instance via a crafted participant_url value containing a
dangerous URI scheme.
To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-31 19:17
Updated : 2026-08-04 14:48
NVD link : CVE-2026-18481
Mitre link : CVE-2026-18481
CVE.ORG link : CVE-2026-18481
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
