logo

CVE-2026-44990: sanitize-html XMP Element XSS Bypass (CVSS 9.3)

ID: 65665a06-825d-56b7-b136-0f3588af3f5d

STIX ID: report--65665a06-825d-56b7-b136-0f3588af3f5d

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

A critical stored XSS vulnerability (CVE-2026-44990, CVSS 9.3) in the sanitize-html Node.js library allows attacker-supplied content placed inside disallowed <xmp> elements to be output unescaped and executed in victims' browsers; versions prior to 2.17.4 are affected, and applications that process user-generated HTML (including ApostropheCMS deployments) are at risk. The advisory includes a technical explanation, an exploit example, detection recommendations (search for <xmp> in user content), and remediation steps—immediately update to [email protected] or apply mitigations while patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.