{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-59167/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jihong88:suneditor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-59167"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SunEditor (\u003c= 2.47.10)"],"_cs_severities":["critical"],"_cs_tags":["xss","web-vulnerability","stored-xss","cve-2026-59167"],"_cs_type":"advisory","_cs_vendors":["JiHong88"],"content_html":"\u003cp\u003eSunEditor versions up to and including 2.47.10 are vulnerable to a critical cross-site scripting (XSS) flaw (CVE-2026-59167). The vulnerability originates from a failure in the library's sanitization logic to properly strip executable event-handler attributes (such as onclick, onmouseover, or onfocus) when they are applied to non-standard, namespaced, or custom HTML elements (e.g., \u0026lt;a:b\u0026gt;).\u003c/p\u003e\n\u003cp\u003eWhen an attacker injects a crafted namespaced element containing an event handler into the editor, the sanitizer fails to normalize or remove the malicious attribute. Consequently, the resulting HTML content, when rendered in a victim's browser, allows for the execution of arbitrary JavaScript upon user interaction. This vulnerability poses a significant risk to applications integrating SunEditor, as it enables stored XSS attacks that can lead to session hijacking, unauthorized actions in the user context, and credential theft. The issue was introduced through changes in the library's sanitization workflow and remains unpatched in versions 2.47.10 and earlier.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for stored XSS, permitting an attacker to execute arbitrary JavaScript within the session of an authenticated user. This can lead to full account takeover, unauthorized modification of the DOM, theft of session tokens, and exfiltration of sensitive information displayed within the application. Organizations leveraging SunEditor for content management or messaging platforms are at high risk if they do not sanitize user-submitted content server-side or upgrade to a fixed version once available.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade SunEditor to a patched version immediately upon release.\u003c/li\u003e\n\u003cli\u003eImplement secondary server-side sanitization for all content submitted through the editor to ensure that malicious attributes are stripped, regardless of whether the client-side library filters them.\u003c/li\u003e\n\u003cli\u003eDeploy a Content Security Policy (CSP) that disallows inline script execution (unsafe-inline) to mitigate the impact of successful XSS injections.\u003c/li\u003e\n\u003cli\u003eEnsure regression tests are integrated into the build pipeline specifically targeting namespaced HTML elements with event-handler attributes to prevent similar sanitization bypasses.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-24T20:04:25Z","date_published":"2026-09-24T20:04:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-suneditor-xss/","summary":"SunEditor versions up to 2.47.10 contain a critical XSS vulnerability (CVE-2026-59167) where insufficient sanitization of namespaced HTML tags allows for arbitrary JavaScript execution via event-handler attributes.","title":"SunEditor Sanitization Bypass Leading to Stored XSS","url":"https://feed.craftedsignal.io/briefs/2026-09-suneditor-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-59167","version":"https://jsonfeed.org/version/1.1"}