Vulnerability GHSA-vj3q-vp3g-j9c8

High Risk
HIGH RISK
CVSS Score: 8.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 days ago
September 25, 2026 at 03:00 PM UTC
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
4.0-BETA1 - 6.5.5 and 7.0.0-beta.1 - 9.22.4
4.0-BETA1 - 6.5.5 and 7.0.0-beta.1 - 9.22.4

Summary

code16/sharp has a stored XSS via data-html-content Sanitizer Bypass

Details

Impact

The vulnerability allows an attacker to bypass the HTML sanitizer by using the data-html-content attribute in the content of a SharpEditorFormField.

Patches

The field must now explicitly configure SharpFormEditorField::RAW_HTML in the toolbar to keep this behavior. When using the RAW_HTML button, the application using code16/sharp must sanitize manually the content coming from the field. Vulnerability has been patched in version 9.22.5.

Workarounds

Sanitize every contents of editors manually (e.g. using Symfony/HtmlSanitizer)

Impacted packages

Timeline

Published
2 days ago
September 25, 2026 at 03:00 PM UTC
Fixed (9.22.5)
3 months ago
June 24, 2026 at 11:59 AM UTC
Last Modified
2 days ago
September 25, 2026 at 03:15 PM UTC