Open OnDemand Files Application Directory Navigation Malicious Input Vulnerability

Vulnerability

A vulnerability exists in the Files application of Open OnDemand, specifically in versions prior to 4.0.9 and 4.1.3. This vulnerability allows for malicious input when users navigate to a directory. The issue has been addressed in versions 4.0.9 and 4.1.3, leaving earlier versions susceptible.

Impact

Exploitation of this vulnerability could lead to the injection of malicious input, potentially causing unintended behavior in the application.

Reproduction

The vulnerability can be reproduced by using Open OnDemand versions prior to 4.0.9 or 4.1.3. Navigate to a directory within the Files application, which will trigger the vulnerability by allowing malicious input to be processed.

Remediation

Users can upgrade to Open OnDemand versions 4.0.9 or 4.1.3 to address this vulnerability.

Added: Mar 4, 2026, 11:21 PM
Updated: Mar 4, 2026, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
1.9
exploitability
6.3
remediation
7.7
relevance
3.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.