Vulnerability GHSA-qxg3-46rw-79j8

High Risk
HIGH RISK
CVSS Score: 7.3
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 days ago
September 25, 2026 at 03:02 PM UTC
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
4.0-BETA1 - 6.5.5 and 7.0.0-beta.1 - 9.22.4
4.0-BETA1 - 6.5.5 and 7.0.0-beta.1 - 9.22.4

Summary

code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute

Details

Impact

A Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on elements.</p> <p>While the underlying Symfony HtmlSanitizer correctly HTML-encodes special characters inside the attribute value (e.g., converting <script> to &lt;script&gt;), the HTML specification mandates that browsers automatically decode HTML entities inside attribute values before processing them. As a result, any encoded JavaScript inside a srcdoc attribute is evaluated and executed as live HTML/JS in the context of the iframe when the page is rendered.</p> <p>An attacker with permissions to edit an Editor field can inject malicious scripts to target other users viewing the content. Potential impacts include:</p> <ul> <li>Session Hijacking (stealing admin session cookies via document.cookie)</li> <li>Account Takeover &amp; Privilege Escalation (e.g., a low-privileged editor triggering actions as an Administrator)</li> <li>Admin panel data theft</li> </ul> <h3>Patches</h3> <p>The vulnerability has been patched in version v9.22.5.</p> <p>The fix explicitly removes srcdoc from the list of allowed iframe attributes in <code>src/Utils/Sanitization/FormatsSanitizedValue.php</code>.</p> <h3>Workarounds</h3> <p>Users who cannot upgrade immediately can manually sanitize all content of editor fields to strip <code>srcdoc</code> attributes.</p>

Impacted packages

Timeline

Published
2 days ago
September 25, 2026 at 03:02 PM UTC
Fixed (9.22.5)
3 months ago
June 24, 2026 at 11:59 AM UTC
Last Modified
2 days ago
September 25, 2026 at 03:15 PM UTC