Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44990

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.1

Описание

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of sanitize-html prior to 2.17.4 can turn attacker-controlled content inside a disallowed xmp element into live HTML or JavaScript. This is a sanitizer bypass in the default disallowedTagsMode: 'discard' path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

A flaw was found in the sanitize-html library. Under its default configuration, an attacker can embed malicious content within a disallowed xmp element. This vulnerability allows the attacker to bypass the HTML sanitization process, leading to stored Cross-Site Scripting (XSS). Successful exploitation can result in arbitrary code execution or information disclosure when a user views the affected content.

Отчет

This is an Important flaw. The sanitize-html library, used in Red Hat products, is susceptible to a stored Cross-Site Scripting (XSS) bypass. Malicious content within a disallowed xmp element can be rendered as live HTML or JavaScript due to a sanitizer bypass in the default configuration. This can lead to arbitrary code execution or information disclosure when affected content is viewed.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesopentelemetry-collectorNot affected
Red Hat Hardened Imagesopentelemetry-collector-contribNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-ui-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleAffected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Affected
Red Hat Satellite 6nodejs-sanitize-htmlNot affected
Red Hat Satellite 6satellite/iop-advisor-frontend-rhel9Affected
multicluster engine for Kubernetes 2.1multicluster-engine/console-mce-rhel9FixedRHSA-2026:4688527.07.2026
multicluster engine for Kubernetes 2.1multicluster-engine/console-mce-rhel9FixedRHSA-2026:4738828.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2488565sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.3
nvd
около 2 месяцев назад

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

CVSS3: 9.3
github
3 месяца назад

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

8.1 High

CVSS3