Answer in brief
CVE-2026-108722 records a Low severity (CVSS 2.3) vulnerability in open-computer-use through commit 610bac8 Stored XSS via log.html Session Log. The current sources do not mark it as known exploited. The current feed maps e2b-dev/open-computer-use (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 2.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps e2b-dev/open-computer-use (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| e2b-dev/open-computer-usegeneric | >=0 <=610bac85d242b2fdf43fbe36bce2348658a2d4c9 | Not reported |
Published upstream
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 11, 2026
open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html without HTML escaping. Attackers controlling sandbox content, such as web pages or files appearing in run_command output, can inject script that runs when operators open the log, exfiltrating transcript contents.
Quoted source text, attributed separately from HOL analysis.