{"id":"CVE-2026-54503","aliases":["PYSEC-2026-3497"],"url":"https://o3.security/vulnerability/CVE-2026-54503","summary":"plone.app.textfield: Stored XSS by spoofing mime type ","details":"### Impact\n\nA stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (`text/x-html-safe`) is the type that signifies \"already sanitized\", any value whose stored mimeType equals it bypasses the safe_html transform entirely on render. The transform itself is sound — it correctly strips `on*` event-handler attributes and `javascript:/data:` URIs; the defect is that it is never invoked for these values. The unsanitized value is then emitted via `tal:content=\"structure ...\"`, which performs no escaping, so the payload executes in the viewer's browser. \n\nThis can be a problem when a RichText field is wrongly defined in code with a `mimeType` and `outputMimeType` that are the same, or when the REST API is used to the same effect.\n\n### Patches\nThe problem has been patched:\n\n* For Plone 6.0, upgrade `plone.app.textfield` to 2.0.2.\n* For Plone 6.1, upgrade `plone.app.textfield` to 3.0.2.\n* For Plone 6.2, upgrade `plone.app.textfield` to 4.0.1.\n\n### Workarounds\nThere is no known workaround.","published":"2026-07-17T18:35:57Z","modified":"2026-07-23T15:11:23.384785972Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"plone-app-textfield","fixedVersion":"2.0.2"},{"ecosystem":"PyPI","name":"plone-app-textfield","fixedVersion":"3.0.2"},{"ecosystem":"PyPI","name":"plone-app-textfield","fixedVersion":"4.0.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/plone/plone.app.textfield/security/advisories/GHSA-4r4f-gg25-rmg5"},{"type":"PACKAGE","url":"https://github.com/plone/plone.app.textfield"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-23T15:11:23.384785972Z"}}