{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-61825/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:code16:sharp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-61823"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sharp (\u003c 9.22.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","vulnerability","cve-2026-61825"],"_cs_type":"advisory","_cs_vendors":["Code16"],"content_html":"\u003cp\u003eCode16 Sharp versions prior to v9.22.5 are vulnerable to a Stored Cross-Site Scripting (XSS) attack originating from improper sanitization of the \u003ccode\u003esrcdoc\u003c/code\u003e attribute on \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e elements within the rich text editor. While the application utilizes the Symfony HtmlSanitizer to encode special characters, the HTML specification forces browsers to decode these HTML entities when processing the \u003ccode\u003esrcdoc\u003c/code\u003e attribute. This behavior effectively nullifies the existing sanitization, allowing attackers to inject and execute arbitrary JavaScript. An attacker with access to the Editor field can exploit this to perform session hijacking, unauthorized account actions, or data theft against other users, including administrative accounts. The vendor has addressed this in version v9.22.5 by explicitly removing \u003ccode\u003esrcdoc\u003c/code\u003e from the list of allowed iframe attributes in the sanitization logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated attackers to perform actions on behalf of other users, including high-privileged administrators. Successful exploitation can lead to full session takeover, persistent unauthorized data access, and potential lateral movement within the administrative dashboard.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Code16 Sharp v9.22.5 or later to apply the patch that removes support for the srcdoc attribute in iframe elements.\u003c/li\u003e\n\u003cli\u003eFor environments unable to upgrade immediately, manually audit and sanitize all content within Editor fields to strip the srcdoc attribute from iframe tags.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers that prevent the execution of inline scripts and restrict iframe sources to trusted domains.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T20:06:52Z","date_published":"2026-09-25T20:06:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sharp-stored-xss/","summary":"A stored XSS vulnerability in the Code16 Sharp rich text editor allows authenticated attackers to execute arbitrary JavaScript by exploiting browser-side HTML entity decoding within the iframe srcdoc attribute.","title":"Stored XSS Vulnerability in Code16 Sharp via iframe srcdoc Attribute","url":"https://feed.craftedsignal.io/briefs/2026-09-sharp-stored-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-61825","version":"https://jsonfeed.org/version/1.1"}