THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xhq9-whgq-49j5 (high) — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

[GHSA] GHSA-xhq9-whgq-49j5 (high) — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

highgithub_advisoriesPublished 2026-09-17

GHSA-xhq9-whgq-49j5 Severity: high CVE: CVE-2026-63459

Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions

**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·

## Summary The dashboard's `RichTextDescriptionCell` "str

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xhq9-whgq-49j5