CVE-2026-22849: Saleor lacks proper HTML sanitization in rich text fields

Published Jan 21, 2026
·
Updated

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors to perform stored XSS attacks on dashboards and storefronts. Malicious staff members could craft script injections to target other staff members, possibly stealing their access and/or refresh tokens. This issue has been patched in versions 3.22.27, 3.21.43, and 3.20.108. In case of inability to upgrade straight away, a possible workaround is to use client-side cleaner.

Affected Software

4 affected components
npm/saleor>3.0.0, <3.20.108
Saleor Saleor>=3.0.0<3.20.108
Saleor Saleor>=3.21.0<3.21.43
Saleor Saleor>=3.22.0<3.22.27

Event History

Jan 21, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 20, 58071
Event
via FIRST·12:07 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-22849?

CVE-2026-22849 has a high severity rating due to the lack of proper HTML sanitization, allowing for possible cross-site scripting attacks.

2

How do I fix CVE-2026-22849?

To fix CVE-2026-22849, upgrade your Saleor installation to versions 3.20.108, 3.21.43, or 3.22.27 or later.

3

Which versions of Saleor are affected by CVE-2026-22849?

Saleor versions starting from 3.0.0 and prior to 3.20.108, 3.21.43, and 3.22.27 are affected by CVE-2026-22849.

4

What type of attacks can CVE-2026-22849 potentially lead to?

CVE-2026-22849 can potentially lead to cross-site scripting (XSS) attacks due to inadequate HTML sanitization.

5

Is there a public advisory for CVE-2026-22849?

Yes, there is a public advisory for CVE-2026-22849 which details the vulnerability and remediation steps.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203