Medium · 6.3 Node.js & npm GHSA-6rf4-v2fh-m6p4 CVE-2026-59167
Critical XSS Sanitizer Bypass in SunEditor (CVE-2026-59167)
A sanitizer bypass in SunEditor versions up to 2.47.10 allows event-handler attributes to survive sanitization on namespaced or custom HTML elements, enabling stored cross-site scripting. The issue is fixed in version 2.47.11.
AI summary
A critical vulnerability has been disclosed in SunEditor, a dependency-free WYSIWYG editor written in vanilla JavaScript. The flaw allows attacker-controlled content to retain executable event-handler attributes despite the editor's built-in sanitization, which can lead to cross-site scripting (XSS) when that content is later rendered and a user interacts with it. The issue has been assigned CVE-2026-59167 and GHSA-6rf4-v2fh-m6p4, and is fixed in SunEditor 2.47.11.
What happened
SunEditor's sanitizer, implemented in src/lib/core.js, does not consistently reject namespaced or custom HTML elements. As a result, event-handler attributes placed on such crafted elements can survive the sanitization process and remain embedded in editor output.
Technical cause
The root cause is an improper neutralization of input during web page generation, classified as CWE-79 (Cross-site Scripting). The sanitizer fails to strip event-handler attributes from namespaced or custom HTML elements, leaving them intact in sanitized output.
Why it matters
When an application renders attacker-controlled SunEditor content and a user interacts with the affected element, the retained event handler can execute arbitrary script in the application's browser origin. This can enable stored cross-site scripting, exposure of sensitive data accessible to the page, or unauthorized actions performed in the user's browser session.
Who is affected
Any application that integrates SunEditor and renders editor-generated content containing attacker-controlled input is potentially affected, particularly where that content is displayed to other users.
Affected versions
All SunEditor (npm package 'suneditor') versions from 0 up to and including 2.47.10 are affected.
Fixes and mitigation
The vulnerability is fixed in SunEditor version 2.47.11. Users should update to this version to ensure the sanitizer correctly rejects namespaced and custom HTML elements carrying event-handler attributes.
Recommended action
Update the 'suneditor' npm package to version 2.47.11 as soon as possible. Until the update is applied, treat any user-supplied or externally sourced content rendered through SunEditor as potentially unsafe, and consider additional output encoding or content security policies as defense in depth.
PatchBriefing score
6.3 / 10 · Medium
Official CVSS: 10.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Why this score
This vulnerability has a maximum CVSS base score of 10 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), reflecting network-exploitable, low-complexity, no-privilege-required access with a scope change and full impact on confidentiality, integrity, and availability. The PatchBriefing score of 6.3 reflects that while the CVSS base score contributes heavily, there is no known exploitation in the wild, no public exploit code, and no EPSS data indicating active exploitation likelihood. The score accounts for the vulnerability being unauthenticated and remotely reachable with no user interaction required beyond rendering and interacting with the malicious content, and that a fix is already available.
Affected versions
- suneditor <= 2.47.10
- vulnerable
- ≥ 2.47.11
- patched
Reported fixes
The vulnerability is fixed in SunEditor version 2.47.11. Users should update to this version to ensure the sanitizer correctly rejects namespaced and custom HTML elements carrying event-handler attributes.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email