GHSA-9mvp-w4rr-5c6x: XSS

Published Sep 9, 2026
·
Updated

Description

A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.

Technical description This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores question.body as a normal translatable string, and the public helper questiontitle returns that value with htmlsafe and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.

<img width="1506" height="1285" alt="decidim-election-01" src="https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21" /> <img width="1540" height="657" alt="decidim-election-02" src="https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f" />

Impact

A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.

Patches

See https://github.com/decidim/decidim/pull/16659

Workarounds

Developers should review their implementation's administrator accesses and not give access to untrustworthy users

Resources

OWASP XSS Injection

Credits

This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.

Affected Software

1 affected componentFixes available
rubygems/decidim-elections<0.32.0
0.32.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygems/decidim-elections to a version that resolves this vulnerability.

    Fixed in 0.32.0

Event History

Sep 9, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What level of access is required to introduce a malicious payload?

An attacker needs a low-privilege, process-scoped administrator account or other election-editor access with permission to manage election questions. They can store malicious markup in an election question.

2

Which users are exposed after a malicious question is saved?

Visitors to public election pages and users of voting booth screens can be exposed, because the saved question content is rendered in their browsers. The payload can execute JavaScript in those visitors' browser sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203