PatchSiren cyber security CVE debrief
CVE-2026-108722 e2b-dev CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:32.616Z and has not been modified since then. CVE-2026-108722 is a stored XSS vulnerability in open-computer-use through commit 610bac8, allowing attackers to inject scripts into log.html. Operators and security teams should assess their exposure and prioritize verification and remediation efforts. The vulnerability is located in the Logger.write_log_file function in os_computer_use/logging.py, which writes transcript text into log.html without proper HTML escaping.
- Vendor
- e2b-dev
- Product
- open-computer-use
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Operators and security teams responsible for open-computer-use deployments, especially those utilizing the logging functionality, should assess their exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-108722 is a stored XSS vulnerability in open-computer-use through commit 610bac8, allowing attackers to inject scripts into log.html. Operators and security teams should prioritize verifying the presence of this vulnerability, updating to the latest version or applying patches, and implementing additional security measures to monitor and protect against potential XSS attacks.
- Exfiltration of transcript contents via injected scripts.
- Potential for attackers to manipulate log content.
- Need for verification of open-computer-use versions and logging practices.
- Prioritization of remediation efforts based on deployment context.
Technical summary
The open-computer-use project through commit 610bac8 contains a stored cross-site scripting (XSS) vulnerability in the Logger.write_log_file function in os_computer_use/logging.py. This function writes transcript text into log.html without proper HTML escaping, allowing attackers to inject malicious scripts. The vulnerability allows attackers controlling sandbox content, such as web pages or files appearing in run_command output, to inject script that runs when operators open the log, exfiltrating transcript contents.
Defensive priority
Operators and security teams should prioritize verifying the presence of this vulnerability in their open-computer-use deployments, especially if they utilize the logging functionality.
Recommended defensive actions
- Verify the presence of the vulnerability in open-computer-use deployments, especially if logging functionality is used.
- Review and update open-computer-use to the latest version or apply patches if available.
- Implement additional security measures to monitor and protect against potential XSS attacks.
- Educate operators on the risks associated with this vulnerability and the importance of secure logging practices.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details about a stored cross-site scripting (XSS) vulnerability in open-computer-use through commit 610bac8. The vulnerability is located in the Logger.write_log_file function in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
open-computer-use through commit 610bac8 Stored XSS via log.html Session Log
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108722.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind03/e2b-open-computer-use-html-log-injection
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/logging.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/sandbox_agent.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/e2b-dev/open-computer-use
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/open-computer-use-through-commit-610bac8-stored-xss-via-log-html-session-log
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.