{"id":"CVE-2021-29434","aliases":["GHSA-wq5h-f9p5-q7fx","PYSEC-2021-114"],"title":"Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields","summary":"Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N","vendor":"wagtail","product":"wagtail","ecosystem":"pip","affected":["wagtail < 2.11.7","wagtail >= 2.12, < 2.12.4"],"patched":["wagtail 2.11.7","wagtail 2.12.4"],"published":"2021-04-20","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:26.868402781Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wq5h-f9p5-q7fx","references":[{"url":"https://github.com/wagtail/wagtail/security/advisories/GHSA-wq5h-f9p5-q7fx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29434"},{"url":"https://github.com/wagtail/wagtail/commit/5c7a60977cba478f6a35390ba98cffc2bd41c8a4"},{"url":"https://github.com/wagtail/wagtail/commit/915f6ed2bd7d53154103cc4424a0f18695cdad6c"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/wagtail/PYSEC-2021-114.yaml"},{"url":"https://github.com/wagtail/wagtail"},{"url":"https://github.com/wagtail/wagtail/compare/v2.11.6...v2.11.7"},{"url":"https://pypi.org/project/wagtail"}],"tags":["osv","pip"],"epss":0.00626,"epssPercentile":0.48645,"ingestedAt":"2026-09-12T03:13:01.737Z","slug":"CVE-2021-29434","body":"## Overview\n\n### Impact\nWhen saving the contents of a rich text field in the admin interface, Wagtail does not apply server-side checks to ensure that link URLs use a valid protocol. A malicious user with access to the admin interface could thus craft a POST request to publish content with `javascript:` URLs containing arbitrary code. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.\n\n### Patches\nPatched versions have been released as Wagtail 2.11.7 (for the LTS 2.11 branch) and Wagtail 2.12.4 (for the current 2.12 branch).\n\n### Workarounds\nFor sites that cannot easily upgrade to a current supported version, the vulnerability can be patched by adding the following code to a `wagtail_hooks.py` module in any installed app:\n\n```python\nfrom draftjs_exporter.dom import DOM\nfrom wagtail.admin.rich_text.converters.html_to_contentstate import ExternalLinkElementHandler, PageLinkElementHandler\nfrom wagtail.core import hooks\nfrom wagtail.core.whitelist import check_url\n\n\ndef link_entity(props):\n    id_ = props.get('id')\n    link_props = {}\n\n    if id_ is not None:\n        link_props['linktype'] = 'page'\n        link_props['id'] = id_\n    else:\n        link_props['href'] = check_url(props.get('url'))\n\n    return DOM.create_element('a', link_props, props['children'])\n\n\n@hooks.register('register_rich_text_features', order=1)\ndef register_link(features):\n    features.register_converter_rule('contentstate', 'link', {\n        'from_database_format': {\n            'a[href]': ExternalLinkElementHandler('LINK'),\n            'a[linktype=\"page\"]': PageLinkElementHandler('LINK'),\n        },\n        'to_database_format': {\n            'entity_decorators': {'LINK': link_entity}\n        }\n    })\n```\n\n### Acknowledgements\nMany thanks to Kevin Breen for reporting this issue.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Visit Wagtail's [support channels](https://docs.wagtail.io/en/stable/support.html)\n* Email us at security@wagtail.io (if you wish to send encrypted email, the public key ID is `0x6ba1e1a86e0f8ce8`)\n\n## Affected packages\n\n- `wagtail < 2.11.7`\n- `wagtail >= 2.12, < 2.12.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `wagtail 2.11.7`\n- `wagtail 2.12.4`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}