CVE-2026-44282: XSS
Description
A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.
Technical description This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores question.body as a normal translatable string, and the public helper questiontitle returns that value with htmlsafe and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.
<img width="1506" height="1285" alt="decidim-election-01" src="https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21" /> <img width="1540" height="657" alt="decidim-election-02" src="https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f" />
Impact
A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.
Patches
See https://github.com/decidim/decidim/pull/16659
Workarounds
Developers should review their implementation's administrator accesses and not give access to untrustworthy users
Resources
OWASP XSS Injection
Credits
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/decidim-electionsto a version that resolves this vulnerability.Fixed in 0.32.0 - Configuration
Update the public elections UI so that the election question titles/body returned by the helper (question_title returning question.body) are not rendered as trusted HTML via html_safe without a sanitization boundary; ensure the stored question.body is treated as untrusted input and is sanitized/escaped before rendering.
Decidim election question rendering (question_title helper) html_safe/sanitization boundary for question.body = Disable use of html_safe without sanitization; render question titles as sanitized text
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privilege process-scoped administrator, or another election editor with rights to manage election questions, can exploit it. The attacker must be able to save content in an election question statement or body.
Which users are exposed to the injected script?
Visitors to public election pages and voting booth screens are exposed when they view an affected question. The stored payload executes in the visitor's browser.
Does exploitation require attacker interaction from the victim?
The attacker needs question-management privileges to store the payload. A victim must then visit a public election page or voting booth screen that renders the affected question.