Vulnerability Description
Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-068-aws/
- https://github.com/aws/aws-ops-wheel/pull/168
- https://github.com/aws/aws-ops-wheel/security/advisories/GHSA-6rr8-cf9x-pj23
FAQ
What is CVE-2026-18481?
CVE-2026-18481 is a vulnerability with a CVSS score of 7.3 (HIGH). Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative contr...
How severe is CVE-2026-18481?
CVE-2026-18481 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18481?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.