Vulnerability GHSA-6rf4-v2fh-m6p4

Critical
CRITICAL RISK
CVSS Score: 10.0
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
3 days ago
September 24, 2026 at 02:57 PM UTC
SunEditor: Critical XSS vulnerability - sanitizer bypass
1.2.0 - 2.47.10
1.2.0 - 2.47.10

Summary

SunEditor: Critical XSS vulnerability - sanitizer bypass

Details

Summary

SUNEDITOR v2.47.10 appears to allow JavaScript execution through crafted namespaced HTML elements.

The sanitization logic does not fully remove executable event-handler attributes from certain custom/namespaced tags. As a result, an attacker may be able to inject HTML content that executes JavaScript when the rendered element is interacted with.

This behavior was observed after the changes introduced in this commit:

https://github.com/JiHong88/suneditor/commit/9ed405fb0de676e56cd0e6a13c19c103ad5948d3

Proof of Concept

The following payload preserves an executable event handler:

<a:b src="/x"><iframe src=javascript:alert(1)></iframe></a:b>

<p><a:b src="/x" onclick="document.body.style.background='red'">click</a:b></p>

Simplified PoC:

<a:b src="/x" onclick="console.log('XSS:',document.domain,document.cookie)">click</a:b>
<p><a:b src="/x" onmouseover="alert('XSS β€” '+document.domain)">πŸ“Ž Click here for solutions</a:b></p>

Impact

This may allow an attacker to inject arbitrary JavaScript into rendered editor content.

Depending on how SUNEDITOR is integrated into an application, this could lead to:

  • Stored XSS
  • DOM manipulation
  • Session theft
  • Credential theft
  • Account takeover actions performed in the victim’s browser context

Suggested Remediation

Possible mitigations include:

  • Normalize DOM elements before sanitization.
  • Explicitly reject or unwrap unknown/custom/namespaced tags.
  • Strip all event-handler attributes from all elements, including unknown/custom elements.
  • Re-validate sanitized output after browser DOM parsing.
  • Add regression tests for namespaced/custom tag payloads.

Impacted packages

Timeline

Published
3 days ago
September 24, 2026 at 02:57 PM UTC
Fixed (2.47.11)
Unknown
Unknown
Last Modified
3 days ago
September 24, 2026 at 03:15 PM UTC