Skip to content

Commit 2b24aea

Browse files
1 parent e4d66a7 commit 2b24aea

2 files changed

Lines changed: 134 additions & 0 deletions

File tree

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,65 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-qxg3-46rw-79j8",
4+
"modified": "2026-09-25T15:02:11Z",
5+
"published": "2026-09-25T15:02:11Z",
6+
"aliases": [
7+
"CVE-2026-61823"
8+
],
9+
"summary": "code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute",
10+
"details": "### Impact\nA Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on <iframe> elements.\n\nWhile the underlying Symfony HtmlSanitizer correctly HTML-encodes special characters inside the attribute value (e.g., converting <script> to &lt;script&gt;), the HTML specification mandates that browsers automatically decode HTML entities inside attribute values before processing them. As a result, any encoded JavaScript inside a srcdoc attribute is evaluated and executed as live HTML/JS in the context of the iframe when the page is rendered.\n\nAn attacker with permissions to edit an Editor field can inject malicious scripts to target other users viewing the content. Potential impacts include:\n\n- Session Hijacking (stealing admin session cookies via document.cookie)\n- Account Takeover & Privilege Escalation (e.g., a low-privileged editor triggering actions as an Administrator)\n- Admin panel data theft\n\n### Patches\nThe vulnerability has been patched in version v9.22.5.\n\nThe fix explicitly removes srcdoc from the list of allowed iframe attributes in `src/Utils/Sanitization/FormatsSanitizedValue.php`.\n\n### Workarounds\nUsers who cannot upgrade immediately can manually sanitize all content of editor fields to strip `srcdoc` attributes.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Packagist",
21+
"name": "code16/sharp"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"fixed": "9.22.5"
32+
}
33+
]
34+
}
35+
]
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://github.com/code16/sharp/security/advisories/GHSA-qxg3-46rw-79j8"
42+
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61823"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/code16/sharp/commit/ec509a22c808a5bd9dfad6a0a85c92ce6f411e21"
50+
},
51+
{
52+
"type": "PACKAGE",
53+
"url": "https://github.com/code16/sharp"
54+
}
55+
],
56+
"database_specific": {
57+
"cwe_ids": [
58+
"CWE-79"
59+
],
60+
"severity": "HIGH",
61+
"github_reviewed": true,
62+
"github_reviewed_at": "2026-09-25T15:02:11Z",
63+
"nvd_published_at": "2026-09-24T19:17:15Z"
64+
}
65+
}
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-v65j-hff3-753c",
4+
"modified": "2026-09-25T15:03:43Z",
5+
"published": "2026-09-25T15:03:43Z",
6+
"aliases": [
7+
"CVE-2026-57440"
8+
],
9+
"summary": "Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled",
10+
"details": "### Summary\nWith $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection.\n\n### Details\nThe iframe assembled [here](https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/blob/a573a16d925ee0ea0d34b360856dc8ab0b88f822/includes/EmbedService/EmbedHtmlFormatter.php#L204-L208) adds the url from `getUrl()` as the src without sanitization.\nThe id regex for the archiveorg service and the url regexes for the wistia and sharepoint services allow for double quotes to be introduced.\n\n### PoC\nUsing double quotes, the src attribute can be escaped.\n```\n<embedvideo service=\"archiveorg\" id='a\" onmouseover=\"alert(document.domain)\" data-x=\"'></embedvideo>\n```\n\n### Impact\nWhen $wgEmbedVideoRequireConsent = false, any user able to edit a page can inject arbitrary JavaScript into an HTML event handler attribute (e.g. onfocus) via parameter. It requires no interaction (autofires via autofocus) and executes in the wiki origin for every visitor to the page.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Packagist",
21+
"name": "starcitizenwiki/embedvideo"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"fixed": "4.1.0"
32+
}
33+
]
34+
}
35+
],
36+
"database_specific": {
37+
"last_known_affected_version_range": "<= 4.0.0"
38+
}
39+
}
40+
],
41+
"references": [
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/security/advisories/GHSA-v65j-hff3-753c"
45+
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57440"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo/commit/370156335b325bb81d14d89edf0a1f2643d50a84"
53+
},
54+
{
55+
"type": "PACKAGE",
56+
"url": "https://github.com/StarCitizenWiki/mediawiki-extensions-EmbedVideo"
57+
}
58+
],
59+
"database_specific": {
60+
"cwe_ids": [
61+
"CWE-79",
62+
"CWE-80"
63+
],
64+
"severity": "HIGH",
65+
"github_reviewed": true,
66+
"github_reviewed_at": "2026-09-25T15:03:43Z",
67+
"nvd_published_at": "2026-09-24T19:17:14Z"
68+
}
69+
}

0 commit comments

Comments
 (0)