Vendure · Vendure · CVE-2026-63459
**Name of the Vulnerable Software and Affected Versions**
Vendure versions prior to 3.6.5
**Description**
Stored cross-site scripting (XSS) exists in the admin dashboard due to unsafe HTML stripping in the `RichTextDescriptionCell` component within `packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx`. The component attempts to remove markup by assigning an administrator-controlled `description` to a live element's `innerHTML` and then reading the `textContent`. This process allows active resource markup, such as `<img src=x onerror=...>`, to execute event handlers during the assignment before the text is read.
A lower-privilege administrator can store malicious markup in the `description` fields of the Products, Collections, Promotions, Payment Methods, or Shipping Methods lists. The script executes when another administrator views the affected row, potentially compromising their session and enabling cross-privilege or cross-channel administrative actions.
**Recommendations**
Update to version 3.6.5.
As a temporary workaround, restrict write permissions for the `description` field in the Products, Collections, Promotions, Payment Methods, and Shipping Methods lists to trusted administrators only.