CVE-2019-9580: Stackstorm

Medium severity, CVSS 6.1. EPSS: 3% chance of exploitation in the next 30 days.

In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

Affected products

  • Stackstorm Stackstorm: before 2.9.3 (fixed in 2.9.3); from 2.10.0, before 2.10.3 (fixed in 2.10.3)

Published 2019-03-09. Last modified 2026-06-17.