THREAT OPS › Threat News › [GHSA] GHSA-w2x5-gv52-9ccv (high) — Sakai Conversations has a Stored XSS Issue
[GHSA] GHSA-w2x5-gv52-9ccv (high) — Sakai Conversations has a Stored XSS Issue
GHSA-w2x5-gv52-9ccv Severity: high CVE: CVE-2026-54049
Sakai Conversations has a Stored XSS Issue
### Summary
The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- 2696b4b48cbef2e81512f52f84f7477adff78b27sha1
- CVE-2026-54049cve
Original source: https://github.com/advisories/GHSA-w2x5-gv52-9ccv