Executive brief
ZenML is an open-source framework for machine learning operations and workflow management. A reflected cross-site scripting (XSS) vulnerability in the survey redirect parameter allows attackers to inject malicious scripts that execute in users' browsers, potentially stealing session cookies and account credentials without authentication.
Technical details
A reflected XSS vulnerability exists in ZenML version 0.57.1 due to improper validation of the 'redirect' parameter in the survey functionality (CWE-79). The vulnerability allows an attacker to craft a malicious URL with unvalidated redirect parameter that, when clicked by a user, executes arbitrary JavaScript in the victim's browser context. The attack vector is network-based and requires user interaction (clicking a malicious link). An attacker can steal cookies, session tokens, or other sensitive data, potentially leading to account takeover. The vulnerability was fixed in version 0.58.0.
Affected products
- ZenML ZenML 0.57.1
Timeline
- 2024-06-30: disclosed
- 2024-05-27: patched: Version 0.58.0 released