top of page
perceptive_background_267k.jpg

Stored cross-site scripting in the participant URL handling in AWS Ops
Wheel before PR #168 might allow an authenticated remote user to steal
session tokens a…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 21:02:18

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Identity & Access

A stored cross-site scripting (XSS) vulnerability exists in AWS Ops Wheel prior to PR #168, specifically in the participant URL handling functionality. An authenticated remote user can exploit this by crafting a malicious participant_url value containing a dangerous URI scheme. Successful exploitation may allow the attacker to steal session tokens and escalate privileges to full administrative control of the deployed instance. The vulnerability is classified as stored XSS, meaning the malicious payload persists on the server and affects other users who encounter it. Remediation requires redeploying from the latest version of aws-ops-wheel. AWS has published a security bulletin and a GitHub security advisory addressing this issue. A pull request (#168) was issued to patch the vulnerability in the upstream repository.

Technical details

Mitigation steps:

Affected products:

AWS Ops Wheel

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page