ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6. | |
| Title | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T19:49:51.903Z
Reserved: 2026-07-17T14:47:08.032Z
Link: CVE-2026-63670
No data.
Status : Received
Published: 2026-08-17T20:16:45.000
Modified: 2026-08-17T20:16:45.000
Link: CVE-2026-63670
No data.
OpenCVE Enrichment
Updated: 2026-08-17T21:45:03Z