Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.3 Node.js & npm GHSA-6rf4-v2fh-m6p4 CVE-2026-59167

Critical XSS Sanitizer Bypass in SunEditor (CVE-2026-59167)

A sanitizer bypass in SunEditor versions up to 2.47.10 allows event-handler attributes to survive sanitization on namespaced or custom HTML elements, enabling stored cross-site scripting. The issue is fixed in version 2.47.11.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A critical vulnerability has been disclosed in SunEditor, a dependency-free WYSIWYG editor written in vanilla JavaScript. The flaw allows attacker-controlled content to retain executable event-handler attributes despite the editor's built-in sanitization, which can lead to cross-site scripting (XSS) when that content is later rendered and a user interacts with it. The issue has been assigned CVE-2026-59167 and GHSA-6rf4-v2fh-m6p4, and is fixed in SunEditor 2.47.11.

What happened

SunEditor's sanitizer, implemented in src/lib/core.js, does not consistently reject namespaced or custom HTML elements. As a result, event-handler attributes placed on such crafted elements can survive the sanitization process and remain embedded in editor output.

Technical cause

The root cause is an improper neutralization of input during web page generation, classified as CWE-79 (Cross-site Scripting). The sanitizer fails to strip event-handler attributes from namespaced or custom HTML elements, leaving them intact in sanitized output.

Why it matters

When an application renders attacker-controlled SunEditor content and a user interacts with the affected element, the retained event handler can execute arbitrary script in the application's browser origin. This can enable stored cross-site scripting, exposure of sensitive data accessible to the page, or unauthorized actions performed in the user's browser session.

Who is affected

Any application that integrates SunEditor and renders editor-generated content containing attacker-controlled input is potentially affected, particularly where that content is displayed to other users.

Affected versions

All SunEditor (npm package 'suneditor') versions from 0 up to and including 2.47.10 are affected.

Fixes and mitigation

The vulnerability is fixed in SunEditor version 2.47.11. Users should update to this version to ensure the sanitizer correctly rejects namespaced and custom HTML elements carrying event-handler attributes.

Recommended action

Update the 'suneditor' npm package to version 2.47.11 as soon as possible. Until the update is applied, treat any user-supplied or externally sourced content rendered through SunEditor as potentially unsafe, and consider additional output encoding or content security policies as defense in depth.

PatchBriefing score

6.3 / 10 · Medium

Official CVSS: 10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Why this score

This vulnerability has a maximum CVSS base score of 10 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), reflecting network-exploitable, low-complexity, no-privilege-required access with a scope change and full impact on confidentiality, integrity, and availability. The PatchBriefing score of 6.3 reflects that while the CVSS base score contributes heavily, there is no known exploitation in the wild, no public exploit code, and no EPSS data indicating active exploitation likelihood. The score accounts for the vulnerability being unauthenticated and remotely reachable with no user interaction required beyond rendering and interacting with the malicious content, and that a fix is already available.

Affected versions

suneditor <= 2.47.10
vulnerable
≥ 2.47.11
patched

Reported fixes

The vulnerability is fixed in SunEditor version 2.47.11. Users should update to this version to ensure the sanitizer correctly rejects namespaced and custom HTML elements carrying event-handler attributes.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Critical XSS Sanitizer Bypass in SunEditor (CVE-2026-59167)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email