{"id":"GHSA-8rqh-vxpr-x77p","title":"plone.restapi: Stored XSS by spoofing mime type","summary":"plone.restapi: Stored XSS by spoofing mime type","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","vendor":"plone-restapi","product":"plone-restapi","ecosystem":"pip","affected":["plone-restapi < 9.15.6","plone-restapi >= 10.0.0, < 10.0.1"],"patched":["plone-restapi 9.15.6","plone-restapi 10.0.1"],"published":"2026-07-17","updated":"2026-07-17","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8rqh-vxpr-x77p","references":[{"url":"https://github.com/plone/plone.app.textfield/security/advisories/GHSA-4r4f-gg25-rmg5"},{"url":"https://github.com/plone/plone.restapi/security/advisories/GHSA-8rqh-vxpr-x77p"},{"url":"https://github.com/plone/plone.restapi"}],"tags":["osv","pip"],"ingestedAt":"2026-07-17T19:00:50.704Z","slug":"GHSA-8rqh-vxpr-x77p","body":"## Overview\n\n### Impact\n\nA stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (`text/x-html-safe`) is the type that signifies \"already sanitized\", any value whose stored mimeType equals it bypasses the safe_html transform entirely on render. The transform itself is sound — it correctly strips `on*` event-handler attributes and `javascript:/data:` URIs; the defect is that it is never invoked for these values. The unsanitized value is then emitted via `tal:content=\"structure ...\"`, which performs no escaping, so the payload executes in the viewer's browser. \n\nThis can be a problem when a RichText field is wrongly defined in code with a `mimeType` and `outputMimeType` that are the same, or when the REST API is used to the same effect.\n\nThis is the same vulnerability as reported in `plone.app.textfield`:\nhttps://github.com/plone/plone.app.textfield/security/advisories/GHSA-4r4f-gg25-rmg5\n\n### Patches\nThe problem has been patched:\n\n* For Plone 6.0 and 6.2, upgrade `plone.restapi` to 9.15.6.\n* For Plone 6.2, upgrade `plone.restapi` to 10.0.1.\n\nThis will prevent abusing the REST API to store wrong rich text values.\n\nThis will **not** prevent XSS from rich text fields that already have wrong values.  For that, you will need a patched `plone.app.textfield` version. See the `plone.app.textfield` advisory linked above for versions.\n\n### Workarounds\nThere is no known workaround.\n\n## Affected packages\n\n- `plone-restapi < 9.15.6`\n- `plone-restapi >= 10.0.0, < 10.0.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `plone-restapi 9.15.6`\n- `plone-restapi 10.0.1`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}