Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55810

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 8.1

Описание

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

A flaw was found in Drupal Plotly.js Graphing. This vulnerability, stemming from improperly controlled modification of dynamically-determined object attributes, allows for object injection. This could enable an attacker to manipulate application data or potentially execute unauthorized code.

Отчет

This Important vulnerability in Drupal Plotly.js Graphing allows object injection, enabling an attacker with low privileges to potentially manipulate application data or execute unauthorized code. This risk is heightened by the network-based attack vector and lack of user interaction required for exploitation, impacting the confidentiality and integrity of Red Hat products such as Ansible Services and Red Hat OpenShift AI.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2499302plotlyjs_graphing: Drupal Plotly.js Graphing: Object Injection Vulnerability

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
25 дней назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

CVSS3: 9.8
github
25 дней назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

8.1 High

CVSS3