GHSA-r4c3-6c67-qqwxMediumCVSS 8.7
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards...
🔗 CVE IDs covered (1)
📋 Description
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-84942
- https://aws.amazon.com/security/security-bulletins/2026-102-aws
- https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/2.19.5
- https://github.com/opensearch-project/OpenSearch-Dashboards/releases/tag/3.6.0
- https://github.com/advisories/GHSA-r4c3-6c67-qqwx