Executive brief
IBM Engineering AI Hub is a platform used for managing AI-driven engineering lifecycles. A critical vulnerability allows remote attackers to execute malicious scripts in a user's browser, which could lead to the theft of sensitive session data, unauthorized actions on behalf of users, or full account takeover. This occurs when the application fails to properly clean data before displaying it on a web page.
Technical details
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are vulnerable to a Cross-Site Scripting (XSS) flaw (CWE-79). The vulnerability stems from improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit this by persuading a user to visit a malicious URL or interact with a crafted page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or data exfiltration. The issue is resolved in version 1.3.0.
Affected products
- IBM Engineering AI Hub 1.0.0, 1.1.0, 1.2.0
Timeline
- 2026-07-17: advisory: IBM published the security bulletin.
- 2026-07-17: disclosed: CVE-2026-15091 published to the NVD.