CVE-2026-44371: Osc Ondemand

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

Affected products

  • Osc Ondemand: before 4.0.11 (fixed in 4.0.11); from 4.1.0, before 4.1.5 (fixed in 4.1.5); from 4.2.0, before 4.2.2 (fixed in 4.2.2)

Published 2026-05-14. Last modified 2026-06-17.