GHSA-9mvp-w4rr-5c6x: XSS
Description
A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.
Technical description This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores question.body as a normal translatable string, and the public helper questiontitle returns that value with htmlsafe and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.
<img width="1506" height="1285" alt="decidim-election-01" src="https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21" /> <img width="1540" height="657" alt="decidim-election-02" src="https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f" />
Impact
A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.
Patches
See https://github.com/decidim/decidim/pull/16659
Workarounds
Developers should review their implementation's administrator accesses and not give access to untrustworthy users
Resources
OWASP XSS Injection
Credits
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/decidim-electionsto a version that resolves this vulnerability.Fixed in 0.32.0
Event History
Frequently Asked Questions
What level of access is required to introduce a malicious payload?
An attacker needs a low-privilege, process-scoped administrator account or other election-editor access with permission to manage election questions. They can store malicious markup in an election question.
Which users are exposed after a malicious question is saved?
Visitors to public election pages and users of voting booth screens can be exposed, because the saved question content is rendered in their browsers. The payload can execute JavaScript in those visitors' browser sessions.