{"id":"CVE-2026-61696","summary":"Forem: Stored XSS in Admin Abuse Report Rendering","details":"Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitted through feedback_message[message] is stored without sanitization and rendered in app/views/admin/feedback_messages/_feedback_message.html.erb through raw(feedback_message.message) when offender_id is present. Viewing the abuse report executes arbitrary JavaScript in an administrator's browser and may expose sensitive in-page data, abuse CSRF tokens, or perform administrative actions in the victim's session. The public FeedbackMessagesController accepts the report without authorization and previously permitted a submitted offender_id, making the vulnerable rendering path reachable by an unauthenticated attacker. This issue is fixed in commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c","aliases":["GHSA-4463-499m-94mx"],"modified":"2026-08-20T03:54:33.107602489Z","published":"2026-08-18T17:57:07.736Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"92eacd16a82cf9007ba8e16a2258b42e3b53ca9c"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"_feedback_message.html.erb"}],"source":"DESCRIPTION"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-74","CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61696.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61696.json"},{"type":"ADVISORY","url":"https://github.com/forem/forem/security/advisories/GHSA-4463-499m-94mx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61696"},{"type":"FIX","url":"https://github.com/forem/forem/commit/92eacd16a82cf9007ba8e16a2258b42e3b53ca9c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/forem/forem","events":[{"introduced":"0"},{"fixed":"92eacd16a82cf9007ba8e16a2258b42e3b53ca9c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["stable.20210804.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61696.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N"}]}