PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108722 e2b-dev CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:32.616Z and has not been modified since then. CVE-2026-108722 is a stored XSS vulnerability in open-computer-use through commit 610bac8, allowing attackers to inject scripts into log.html. Operators and security teams should assess their exposure and prioritize verification and remediation efforts. The vulnerability is located in the Logger.write_log_file function in os_computer_use/logging.py, which writes transcript text into log.html without proper HTML escaping.

Vendor
e2b-dev
Product
open-computer-use
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Operators and security teams responsible for open-computer-use deployments, especially those utilizing the logging functionality, should assess their exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-108722 is a stored XSS vulnerability in open-computer-use through commit 610bac8, allowing attackers to inject scripts into log.html. Operators and security teams should prioritize verifying the presence of this vulnerability, updating to the latest version or applying patches, and implementing additional security measures to monitor and protect against potential XSS attacks.

  • Exfiltration of transcript contents via injected scripts.
  • Potential for attackers to manipulate log content.
  • Need for verification of open-computer-use versions and logging practices.
  • Prioritization of remediation efforts based on deployment context.

Technical summary

The open-computer-use project through commit 610bac8 contains a stored cross-site scripting (XSS) vulnerability in the Logger.write_log_file function in os_computer_use/logging.py. This function writes transcript text into log.html without proper HTML escaping, allowing attackers to inject malicious scripts. The vulnerability allows attackers controlling sandbox content, such as web pages or files appearing in run_command output, to inject script that runs when operators open the log, exfiltrating transcript contents.

Defensive priority

Operators and security teams should prioritize verifying the presence of this vulnerability in their open-computer-use deployments, especially if they utilize the logging functionality.

Recommended defensive actions

  • Verify the presence of the vulnerability in open-computer-use deployments, especially if logging functionality is used.
  • Review and update open-computer-use to the latest version or apply patches if available.
  • Implement additional security measures to monitor and protect against potential XSS attacks.
  • Educate operators on the risks associated with this vulnerability and the importance of secure logging practices.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and source item provide details about a stored cross-site scripting (XSS) vulnerability in open-computer-use through commit 610bac8. The vulnerability is located in the Logger.write_log_file function in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108722 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108722

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108722 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108722

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • open-computer-use through commit 610bac8 Stored XSS via log.html Session Log

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108722.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind03/e2b-open-computer-use-html-log-injection

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/logging.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/e2b-dev/open-computer-use/blob/610bac85d242b2fdf43fbe36bce2348658a2d4c9/os_computer_use/sandbox_agent.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/e2b-dev/open-computer-use

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/open-computer-use-through-commit-610bac8-stored-xss-via-log-html-session-log

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.