OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.
History

Fri, 10 Apr 2026 08:15:00 +0000

Type Values Removed Values Added
Description OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-10T07:33:08.485Z

Reserved: 2026-04-10T00:00:00.000Z

Link: CVE-2026-40212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-10T08:16:25.850

Modified: 2026-04-10T08:16:25.850

Link: CVE-2026-40212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.