CVE-2026-44990: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms sanitize-html
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
AI Analysis
Technical Summary
CVE-2026-44990 describes a critical cross-site scripting vulnerability in the sanitize-html package used by ApostropheCMS. Versions before 2.17.4, under the default 'disallowedTagsMode: discard' configuration, fail to properly neutralize attacker-controlled content inside disallowed <xmp> elements. This results in a sanitizer bypass that can cause stored XSS when sanitized content is rendered back to users. The vulnerability has a CVSS 3.1 score of 9.3, indicating high exploitability and impact on confidentiality and integrity. The issue is fixed in version 2.17.4.
Potential Impact
Successful exploitation allows an attacker to inject and execute arbitrary HTML or JavaScript in the context of users viewing sanitized content, leading to stored cross-site scripting. This can compromise user confidentiality and integrity of the application data. The vulnerability does not affect availability. No known exploits in the wild have been reported.
Mitigation Recommendations
A security fix is available in sanitize-html version 2.17.4. Users and administrators should upgrade to version 2.17.4 or later to remediate this vulnerability. Patch status is confirmed by the vendor advisory. No alternative mitigations or workarounds are indicated in the advisory.
CVE-2026-44990: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms sanitize-html
Description
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
CVSS v3.1
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44990 describes a critical cross-site scripting vulnerability in the sanitize-html package used by ApostropheCMS. Versions before 2.17.4, under the default 'disallowedTagsMode: discard' configuration, fail to properly neutralize attacker-controlled content inside disallowed <xmp> elements. This results in a sanitizer bypass that can cause stored XSS when sanitized content is rendered back to users. The vulnerability has a CVSS 3.1 score of 9.3, indicating high exploitability and impact on confidentiality and integrity. The issue is fixed in version 2.17.4.
Potential Impact
Successful exploitation allows an attacker to inject and execute arbitrary HTML or JavaScript in the context of users viewing sanitized content, leading to stored cross-site scripting. This can compromise user confidentiality and integrity of the application data. The vulnerability does not affect availability. No known exploits in the wild have been reported.
Mitigation Recommendations
A security fix is available in sanitize-html version 2.17.4. Users and administrators should upgrade to version 2.17.4 or later to remediate this vulnerability. Patch status is confirmed by the vendor advisory. No alternative mitigations or workarounds are indicated in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-08T16:23:33.265Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-44990","vendor":"Red Hat"}]
Threat ID: 6a2c7589e617e2d834c30b62
Added to database: 06/12/2026, 21:09:29 UTC
Last enriched: 07/24/2026, 22:08:43 UTC
Last updated: 07/31/2026, 20:26:54 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.