Summary
GeoNode: Stored XSS to full account takeover
Advisory details
An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a request to change another user's email address to perform a full account takeover. Due to the script element not impacting the CORS policy, requests will succeed.
References
- https://github.com/advisories/GHSA-rwcv-whm8-fmxm
- https://github.com/GeoNode/geonode/security/advisories/GHSA-rwcv-whm8-fmxm
- https://nvd.nist.gov/vuln/detail/CVE-2024-27091
- https://github.com/GeoNode/geonode/commit/e53bdeff331f4b577918927d60477d4b50cca02f
- https://github.com/pypa/advisory-database/tree/main/vulns/geonode/PYSEC-2024-320.yaml
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
- MEDIUMCVE-2026-73295
Material for MkDocs: DOM XSS in search suggestions via query parameter
- HIGHGHSA-99rq-75j6-5j9f
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
- MEDIUMCVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
- MEDIUMCVE-2026-82396
Sulu: Stored XSS via media download inline-disposition override
- MEDIUMGHSA-cp6q-959q-f8rh
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes