CVE-2026-18481
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
31/07/2026
Last modified:
31/07/2026
Description
Stored cross-site scripting in the participant URL handling in AWS Ops <br />
Wheel before PR #168 might allow an authenticated remote user to steal <br />
session tokens and escalate to full administrative control of the <br />
deployed instance via a crafted participant_url value containing a <br />
dangerous URI scheme.<br />
<br />
<br />
<br />
<br />
<br />
<br />
To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Impact
Base Score 4.0
6.20
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH



