VDB
Sign up
MEDIUM6.1

PYSEC-2026-1718

OMERO.web must check that the JSONP callback is a valid function

Quick fix

PYSEC-2026-1718 — omero-web: upgrade to the fixed version with the command below.

pip install --upgrade 'omero-web>=5.26.0'

Details

### Background

There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. One such endpoint is `/webclient/imgData/...`. As we only really use these endpoints with jQuery's own callback name generation [^1] it is quite difficult or even impossible to exploit this in vanilla OMERO.web. However, these metadata endpoints are likely to be used by many plugins.

[^1]: https://learn.jquery.com/ajax/working-with-jsonp/

### Impact OMERO.web before 5.25.0

### Patches Users should upgrade to 5.26.0 or higher ### Workarounds

None

### References * https://stackoverflow.com/questions/2777021/do-i-need-to-sanitize-the-callback-parameter-from-a-jsonp-call * https://stackoverflow.com/questions/1661197/what-characters-are-valid-for-javascript-variable-names

For more information If you have any questions or comments about this advisory:

Open an issue in [omero-web](https://github.com/ome/omero-web) Email us at [security@openmicroscopy.org](mailto:security@openmicroscopy.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/omero-web
Introduced in: 0Fixed in: 5.26.0
Fixpip install --upgrade 'omero-web>=5.26.0'

References