Vulnerability GHSA-6rf4-v2fh-m6p4
Summary
SunEditor: Critical XSS vulnerability - sanitizer bypass
Details
Summary
SUNEDITOR v2.47.10 appears to allow JavaScript execution through crafted namespaced HTML elements.
The sanitization logic does not fully remove executable event-handler attributes from certain custom/namespaced tags. As a result, an attacker may be able to inject HTML content that executes JavaScript when the rendered element is interacted with.
This behavior was observed after the changes introduced in this commit:
https://github.com/JiHong88/suneditor/commit/9ed405fb0de676e56cd0e6a13c19c103ad5948d3
Proof of Concept
The following payload preserves an executable event handler:
<a:b src="/x"><iframe src=javascript:alert(1)></iframe></a:b>
<p><a:b src="/x" onclick="document.body.style.background='red'">click</a:b></p>
Simplified PoC:
<a:b src="/x" onclick="console.log('XSS:',document.domain,document.cookie)">click</a:b>
<p><a:b src="/x" onmouseover="alert('XSS β '+document.domain)">π Click here for solutions</a:b></p>
Impact
This may allow an attacker to inject arbitrary JavaScript into rendered editor content.
Depending on how SUNEDITOR is integrated into an application, this could lead to:
- Stored XSS
- DOM manipulation
- Session theft
- Credential theft
- Account takeover actions performed in the victimβs browser context
Suggested Remediation
Possible mitigations include:
- Normalize DOM elements before sanitization.
- Explicitly reject or unwrap unknown/custom/namespaced tags.
- Strip all event-handler attributes from all elements, including unknown/custom elements.
- Re-validate sanitized output after browser DOM parsing.
- Add regression tests for namespaced/custom tag payloads.
Related Vulnerabilities
Other vulnerabilities affecting the same packages