GHSA-2rp4-x2j7-qmcc: XSS

Published Aug 6, 2026
·
Updated

The control-panel helper that renders element chip/card labels writes an element's draftName into the page without HTML-encoding it, while the surrounding path segments are encoded.

A low-privilege control-panel user who can create a draft of an element (for example, an entry) controls the draft name, so they can store an XSS payload that executes in the browser of any other control-panel user who is shown that element’s chip or card (element indexes with drafts visible, relation and element-selection fields that reference the element, and the drafts list).

This allows a low-privilege author to run JavaScript in an administrator’s authenticated session and take over the control panel. It is the same output-encoding class as the recently fixed GHSA-xrqc-p465-2xvg (Structure entry title) and GHSA-3x4w-mxpf-fhqq (revision context menu), which encoded other user-controlled titles but not the draft name.

Prerequisites

- A control-panel account with permission to edit entries in at least one section and create drafts. - A higher-privileged user (for example, an administrator) who is later shown the draft’s chip or card (an element index with drafts visible, or a relation/element-selection field referencing the element).

Limitations

- Requires the victim to be shown the affected element's chip/card in the control panel (normal day-to-day activity; element indexes and relation fields are routine). - The payload runs in the control-panel origin in the victim’s session.

Impact

A low-privilege author can run arbitrary JavaScript in the session of any higher-privileged control-panel user who is shown the element’s chip or card, including administrators. This is a cross-privilege stored XSS, not a self-XSS: the attacker and the victim are different users, and the payload fires during routine browsing of element indexes and relation fields.

Because the script runs in the victim’s control-panel origin, it can read the CSRF token that Craft embeds in the page JavaScript (Craft.csrfTokenValue, confirmed present on control-panel pages) and issue authenticated control-panel actions as the victim. This was verified end-to-end on Craft Pro: an in-session request to the users/save-user action created a brand new account (User saved., HTTP 200), an admin-only capability that an author can never perform directly.

Affected Software

1 affected componentFixes available
composer/craftcms/cms>=5.0.0-RC1<5.10.8
5.10.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/craftcms/cms to a version that resolves this vulnerability.

    Fixed in 5.10.8

Event History

Aug 6, 2026
Advisory Published
via GitHub·09:33 PM
Data Sourced
via GitHub·09:33 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-2rp4-x2j7-qmcc?

The severity of GHSA-2rp4-x2j7-qmcc is rated at 80, indicating a high risk of exploitation.

2

What vulnerabilities are associated with GHSA-2rp4-x2j7-qmcc?

GHSA-2rp4-x2j7-qmcc is associated with cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities.

3

How do I fix GHSA-2rp4-x2j7-qmcc?

To fix GHSA-2rp4-x2j7-qmcc, ensure that the element's `draftName` is properly HTML-encoded before being rendered on the page.

4

Who is affected by the GHSA-2rp4-x2j7-qmcc vulnerability?

The GHSA-2rp4-x2j7-qmcc vulnerability affects low-privilege control-panel users who can create drafts of elements in Craft CMS.

5

What software does GHSA-2rp4-x2j7-qmcc impact?

GHSA-2rp4-x2j7-qmcc impacts the Craft CMS software, particularly versions prior to the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203