https://seclists.org/oss-sec/2026/q3/955: CVE-2026-91204: Apache Roller: Stod javascript: URI in HTML comments
Affected Software
Frequently Asked Questions
Which deployments are affected?
Only Apache Roller 6.1.5 sites that enable HTML in comments with users.comments.htmlenabled=true and use the HTMLSubset comment formatter are affected. Sites without that combination are not described as affected.
What does an attacker need to exploit this issue?
An unauthenticated remote attacker can submit a stored comment containing a javascript: URI link. Script execution requires a visitor to click the malicious link in the published comment.
Does comment moderation prevent exploitation?
Moderation delays publication where it is enabled. The provided information does not state that moderation removes or neutralizes the malicious link.
What should be done if the affected configuration is in use?
Upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https, and mailto URIs. If upgrading cannot happen immediately, disabling HTML in comments or no longer using the HTMLSubset comment formatter removes the stated affected configuration.