THREAT OPS › Threat News › [GHSA] GHSA-xhq9-whgq-49j5 (high) — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
[GHSA] GHSA-xhq9-whgq-49j5 (high) — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
GHSA-xhq9-whgq-49j5 Severity: high CVE: CVE-2026-63459
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions
**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·
## Summary The dashboard's `RichTextDescriptionCell` "str
Indicators of compromise
- CVE-2026-63459cve
- https://attacker.example/url
Original source: https://github.com/advisories/GHSA-xhq9-whgq-49j5