THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w2x5-gv52-9ccv (high) — Sakai Conversations has a Stored XSS Issue

[GHSA] GHSA-w2x5-gv52-9ccv (high) — Sakai Conversations has a Stored XSS Issue

highgithub_advisoriesPublished 2026-08-24

GHSA-w2x5-gv52-9ccv Severity: high CVE: CVE-2026-54049

Sakai Conversations has a Stored XSS Issue

### Summary

The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w2x5-gv52-9ccv