CVE-2023-45885: Nasa Openmct

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

Affected products

  • Nasa Openmct: up to and including 3.1.0

Published 2023-11-09. Last modified 2026-06-17.