{"id":"CVE-2026-63670","title":"ApostropheCMS is an open-source Node.js content management system","summary":"ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a li…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"sanitize-html","product":"sanitize-html","affected":["sanitize-html <= 2.17.5"],"patched":["sanitize-html 2.17.6"],"published":"2026-08-17","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:11:46.833","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63670","references":[{"url":"https://github.com/apostrophecms/apostrophe/commit/eae1fb2b72ec5d1c27d0977509c6482a0408f725","label":"security-advisories@github.com"},{"url":"https://github.com/apostrophecms/apostrophe/pull/5501","label":"security-advisories@github.com"},{"url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-jxwj-j7wr-gfrw","label":"security-advisories@github.com"},{"url":"https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-jxwj-j7wr-gfrw","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63670"},{"url":"https://github.com/advisories/GHSA-jxwj-j7wr-gfrw"}],"tags":["nvd","ghsa","npm"],"epss":0.00289,"epssPercentile":0.21739,"aliases":["GHSA-jxwj-j7wr-gfrw"],"ecosystem":"npm","ingestedAt":"2026-09-03T20:08:06.422Z","slug":"CVE-2026-63670","body":"## Overview\n\nApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-63670)\n\nAffected packages:\n\n- `sanitize-html <= 2.17.5`\n\nPatched in:\n\n- `sanitize-html 2.17.6`\n\nSource: https://github.com/advisories/GHSA-jxwj-j7wr-gfrw","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}