CVE-2026-44990: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms sanitize-html
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
AI Analysis
Technical Summary
The sanitize-html library used by ApostropheCMS has a sanitizer bypass vulnerability in versions before 2.17.4. Under the default configuration (disallowedTagsMode: 'discard'), malicious content embedded inside a disallowed xmp element can be transformed into executable HTML or JavaScript, resulting in stored XSS. This vulnerability allows attackers to inject scripts that execute in the context of users viewing the sanitized content, potentially leading to arbitrary code execution or data leakage. The issue is tracked as CVE-2026-44990 with a CVSS 3.1 score of 9.3 (critical). Red Hat advisories confirm the vulnerability and note that version 2.17.4 patches the flaw. No mitigation other than upgrading is currently recommended by Red Hat.
Potential Impact
This vulnerability enables attackers to bypass HTML sanitization and inject stored cross-site scripting payloads. When users view the affected sanitized content, the malicious scripts can execute, potentially leading to arbitrary code execution or unauthorized disclosure of sensitive information. The impact includes compromise of confidentiality and integrity of user data and possible session hijacking or other malicious actions performed in the context of the victim's browser.
Mitigation Recommendations
A patch is available in sanitize-html version 2.17.4. Users and administrators should upgrade to version 2.17.4 or later to remediate this vulnerability. Red Hat advisories indicate no effective mitigation other than applying the official fix. No temporary workaround meeting Red Hat's criteria is currently available.
CVE-2026-44990: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in apostrophecms sanitize-html
Description
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
CVSS v3.1
Score 9.3critical
Affected software
apostrophecms
sanitize-html
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sanitize-html library used by ApostropheCMS has a sanitizer bypass vulnerability in versions before 2.17.4. Under the default configuration (disallowedTagsMode: 'discard'), malicious content embedded inside a disallowed xmp element can be transformed into executable HTML or JavaScript, resulting in stored XSS. This vulnerability allows attackers to inject scripts that execute in the context of users viewing the sanitized content, potentially leading to arbitrary code execution or data leakage. The issue is tracked as CVE-2026-44990 with a CVSS 3.1 score of 9.3 (critical). Red Hat advisories confirm the vulnerability and note that version 2.17.4 patches the flaw. No mitigation other than upgrading is currently recommended by Red Hat.
Potential Impact
This vulnerability enables attackers to bypass HTML sanitization and inject stored cross-site scripting payloads. When users view the affected sanitized content, the malicious scripts can execute, potentially leading to arbitrary code execution or unauthorized disclosure of sensitive information. The impact includes compromise of confidentiality and integrity of user data and possible session hijacking or other malicious actions performed in the context of the victim's browser.
Mitigation Recommendations
A patch is available in sanitize-html version 2.17.4. Users and administrators should upgrade to version 2.17.4 or later to remediate this vulnerability. Red Hat advisories indicate no effective mitigation other than applying the official fix. No temporary workaround meeting Red Hat's criteria is currently available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-08T16:23:33.265Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-44990","vendor":"Red Hat"}]
Threat ID: 6a2c7589e617e2d834c30b62
Added to database: 06/12/2026, 21:09:29 UTC
Last enriched: 08/16/2026, 14:17:02 UTC
Last updated: 09/14/2026, 22:11:27 UTC
Views: 172
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.