Airbnb's disclosed vulnerabilities center on internal infrastructure and developer-facing products such as its knowledge repository and monitoring tools, reflecting a relatively contained exposure scope. The observed weakness classes—untrusted deserialization and cross-site scripting—are typical of web-facing and data-handling systems and recur across these products; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airbnb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41875CRITICAL A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payload | Nov 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-12104MEDIUM Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demo | Jun 17, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airbnb.
Media articles that mention a CVE ID that affects a product developed by Airbnb — matched by CVE ID, not by vendor name.