CVE-2024-22854: Darktrace Threat Visualizer

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.

Affected products

  • Darktrace Threat Visualizer: up to and including 6.1.27

Published 2024-02-16. Last modified 2026-06-17.