Summary
plone.app.textfield: Stored XSS by spoofing mime type
Advisory details
Impact
A stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (text/x-html-safe) is the type that signifies "already sanitized", any value whose stored mimeType equals it bypasses the safe_html transform entirely on render. The transform itself is sound — it correctly strips on* event-handler attributes and javascript:/data: URIs; the defect is that it is never invoked for these values. The unsanitized value is then emitted via tal:content="structure ...", which performs no escaping, so the payload executes in the viewer's browser.
This can be a problem when a RichText field is wrongly defined in code with a mimeType and outputMimeType that are the same, or when the REST API is used to the same effect.
Patches
The problem has been patched:
- For Plone 6.0, upgrade
plone.app.textfieldto 2.0.2. - For Plone 6.1, upgrade
plone.app.textfieldto 3.0.2. - For Plone 6.2, upgrade
plone.app.textfieldto 4.0.1.
Workarounds
There is no known workaround.
References
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-55696
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
- MEDIUMCVE-2026-65841
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
- MEDIUMCVE-2026-54570
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
- MEDIUMGHSA-8rqh-vxpr-x77p
plone.restapi: Stored XSS by spoofing mime type
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation