CVE-2024-52281High· 8.9▾ TwilightRancher UI has Stored Cross-site Scripting vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 49 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
A vulnerability has been identified within Rancher UI that allows a malicious actor to perform a Stored XSS attack through the cluster description field.
Please consult the associated MITRE ATT&CK - Technique - Drive-by Compromise for further information about this category of attack.
The fix introduces new changes in the directives responsible for sanitizing HTML code before rendering.
We replaced the v-tooltip directive with the v-clean-tooltip directive.
Patched versions include releases 2.9.4 and 2.10.0.
There are no workarounds for this issue. Users are recommended to upgrade, as soon as possible, to a version of /Rancher Manager which contains the fixes.
This issue was identified and reported by Bhavin Makwana from Workday’s Cyber Defence Team.
If you have any questions or comments about this advisory:
github.com/rancher/rancher >= 2.9.0, < 2.9.4Upgrade to a patched release:
github.com/rancher/rancher 2.9.4Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header