CVE-2026-45572
Decidim: HTML content blocks allow stored script execution
描述
## Description A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the public page renders it with `html_safe` and no output escaping. ## Technical description This issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an `HTML block`. The block is then rendered back through `Decidim::ContentBlocks::HtmlCell#html_content` without a sanitization boundary, so the script executes later in visitor's browsers. <img width="1541" height="439" alt="decidim-html-xss-01" src="https://github.com/user-attachments/assets/acae1c06-8acb-49be-ab12-aabae33190ce" /> <img width="1540" height="752" alt="decidim-html-xss-02" src="https://github.com/user-attachments/assets/a2f1fa7f-03f3-4d17-b58b-f4db865443e9" /> ### Impact - A user with landing-page editing rights for an affected scope can persist JavaScript that executes in visitor's browsers on that page. - Because exploitation already requires privileged administrative access, the practical risk is lower than a participant-controlled or unauthenticated stored XSS. It still creates a browser-execution primitive in a trusted admin-editable surface. ### Patches See https://github.com/decidim/decidim/pull/16451 ### Workarounds Do not give admin permissions to non-trustful users. ### Reference Stored XSS ### Credits This issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicallyopensecurity.com/) against Decidim financed by [NGI](https://ngi.eu/).
如何修補 CVE-2026-45572
要修補 CVE-2026-45572,請將受影響套件升級到下列已修補版本。
- —升級至 0.30.9 或更新版本
CVE-2026-45572 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-45572 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0, < 0.30.9