PT-2026-94343 · Vendure · Vendure

·

CVE-2026-63459

·

Published

2026-09-17

·

Updated

2026-10-01

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vendure versions prior to 3.6.5
Description Stored cross-site scripting (XSS) exists in the admin dashboard due to unsafe HTML stripping in the RichTextDescriptionCell component within packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx. The component attempts to remove markup by assigning an administrator-controlled description to a live element's innerHTML and then reading the textContent. This process allows active resource markup, such as <img src=x onerror=...>, to execute event handlers during the assignment before the text is read.
A lower-privilege administrator can store malicious markup in the description fields of the Products, Collections, Promotions, Payment Methods, or Shipping Methods lists. The script executes when another administrator views the affected row, potentially compromising their session and enabling cross-privilege or cross-channel administrative actions.
Recommendations Update to version 3.6.5. As a temporary workaround, restrict write permissions for the description field in the Products, Collections, Promotions, Payment Methods, and Shipping Methods lists to trusted administrators only.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63459
GHSA-XHQ9-WHGQ-49J5

Affected Products

Vendure