CVE-2026-44990: sanitize-html XMP Element XSS Bypass (CVSS 9.3)
ID: 65665a06-825d-56b7-b136-0f3588af3f5d
STIX ID: report--65665a06-825d-56b7-b136-0f3588af3f5d
Feed Name: CosmicBytez Labs
A critical stored XSS vulnerability (CVE-2026-44990, CVSS 9.3) in the sanitize-html Node.js library allows attacker-supplied content placed inside disallowed <xmp> elements to be output unescaped and executed in victims' browsers; versions prior to 2.17.4 are affected, and applications that process user-generated HTML (including ApostropheCMS deployments) are at risk. The advisory includes a technical explanation, an exploit example, detection recommendations (search for <xmp> in user content), and remediation steps—immediately update to [email protected] or apply mitigations while patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
