CVE-2026-44282: XSS

Published Sep 9, 2026
·
Updated

Description

A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.

Technical description This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores question.body as a normal translatable string, and the public helper questiontitle returns that value with htmlsafe and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.

<img width="1506" height="1285" alt="decidim-election-01" src="https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21" /> <img width="1540" height="657" alt="decidim-election-02" src="https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f" />

Impact

A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.

Patches

See https://github.com/decidim/decidim/pull/16659

Workarounds

Developers should review their implementation's administrator accesses and not give access to untrustworthy users

Resources

OWASP XSS Injection

Credits

This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.

Affected Software

1 affected componentFixes available
rubygems/decidim-elections<0.32.0
0.32.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygems/decidim-elections to a version that resolves this vulnerability.

    Fixed in 0.32.0
  2. Configuration

    Update the public elections UI so that the election question titles/body returned by the helper (question_title returning question.body) are not rendered as trusted HTML via html_safe without a sanitization boundary; ensure the stored question.body is treated as untrusted input and is sanitized/escaped before rendering.

    Decidim election question rendering (question_title helper) html_safe/sanitization boundary for question.body = Disable use of html_safe without sanitization; render question titles as sanitized text

Event History

Sep 9, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

A low-privilege process-scoped administrator, or another election editor with rights to manage election questions, can exploit it. The attacker must be able to save content in an election question statement or body.

2

Which users are exposed to the injected script?

Visitors to public election pages and voting booth screens are exposed when they view an affected question. The stored payload executes in the visitor's browser.

3

Does exploitation require attacker interaction from the victim?

The attacker needs question-management privileges to store the payload. A victim must then visit a public election page or voting booth screen that renders the affected question.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203