{"id":"CVE-2026-59167","published":"2026-09-23T14:17:07.923","lastModified":"2026-09-24T15:17:25.303","description":"SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/JiHong88/suneditor/commit/a94ace269c7102bfb6de58a27a6547bc4eb09045","tags":[]},{"url":"https://github.com/JiHong88/suneditor/issues/1646","tags":[]},{"url":"https://github.com/JiHong88/suneditor/releases/tag/2.47.11","tags":[]},{"url":"https://github.com/JiHong88/suneditor/security/advisories/GHSA-6rf4-v2fh-m6p4","tags":[]},{"url":"https://github.com/JiHong88/suneditor/security/advisories/GHSA-6rf4-v2fh-m6p4","tags":[]}],"exploitRefs":[{"url":"https://github.com/JiHong88/suneditor/commit/a94ace269c7102bfb6de58a27a6547bc4eb09045","tags":[]},{"url":"https://github.com/JiHong88/suneditor/issues/1646","tags":[]},{"url":"https://github.com/JiHong88/suneditor/releases/tag/2.47.11","tags":[]},{"url":"https://github.com/JiHong88/suneditor/security/advisories/GHSA-6rf4-v2fh-m6p4","tags":[]},{"url":"https://github.com/JiHong88/suneditor/security/advisories/GHSA-6rf4-v2fh-m6p4","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in SunEditor allows event-handler attributes to remain on crafted elements, enabling stored cross-site scripting and potentially leading to data exposure or unauthorized actions.","exploitability":"Exploitation is moderately hard as it requires crafting specific HTML elements with event handlers, but preconditions include the application rendering attacker-controlled content.","blast_radius":"If exploited, this could lead to significant data exposure or unauthorized actions within the application's browser context, impacting user data and application integrity.","remediation":"Upgrade to version 2.47.11 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","editor","sanitization"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:46:38.770Z"}}