Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.8 PHP packages GHSA-vj3q-vp3g-j9c8 CVE-2026-61825 PKSA-p6zx-3z97-z7f8 GHSA-qxg3-46rw-79j8

Two Stored XSS Vulnerabilities Patched in code16/Sharp Admin Framework

Sharp, a Laravel-based CMS/admin framework, fixed two stored cross-site scripting vulnerabilities in its rich-text editor component. Both are resolved in version 9.22.5.

AI summary

code16 Sharp, a Laravel-based framework used to build content-management and administrative interfaces, has received a security update addressing two separate stored cross-site scripting (XSS) vulnerabilities in its rich-text editor functionality. Both issues affect versions of Sharp prior to 9.22.5 and have been resolved in that release. Neither vulnerability is currently known to be exploited in the wild, and no public exploit code has been reported.

What Happened

Two stored XSS vulnerabilities were disclosed in code16/Sharp's `SharpEditorFormField` rich-text editor component. CVE-2026-61825 involves attacker-controlled content bearing a `data-html-content` attribute bypassing HTML sanitization, allowing executable markup to persist and run when another user views the stored content. CVE-2026-61823 involves the HTML sanitizer permitting the `srcdoc` attribute on iframe elements; although the markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, which allows an authenticated user with Editor field permissions to store JavaScript that executes when another user views the content.

Technical Cause

Both vulnerabilities are classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). CVE-2026-61825 stems from a sanitizer bypass specific to the `data-html-content` attribute, which can preserve executable markup despite sanitization. CVE-2026-61823 stems from the sanitizer's allowlist permitting the `srcdoc` attribute on iframes; browsers decode HTML entities within that attribute before rendering it as a document, defeating the encoding-based mitigation.

Why It Matters

CVE-2026-61825 carries a CVSS score of 8.7, reflecting a scope-changed impact (the vulnerability can affect resources beyond the vulnerable component itself) with high confidentiality and integrity impact. CVE-2026-61823 carries a CVSS score of 7.3, also with high confidentiality and integrity impact, but without a scope change. The advisory for CVE-2026-61823 notes that successful exploitation could lead to session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data when a victim with elevated access views the stored malicious content.

Who Is Affected

Any application using code16/sharp versions before 9.22.5 that relies on the rich-text editor's `SharpEditorFormField` component is affected. This includes applications that intentionally enable `SharpFormEditorField::RAW_HTML`, which the vendor notes must continue to sanitize editor content independently even after patching.

Affected Versions

code16/sharp versions prior to 9.22.5 are affected by both vulnerabilities. Version 9.22.5 contains the fix for both CVE-2026-61825 and CVE-2026-61823.

Fixes and Mitigation

The vendor has released version 9.22.5, which patches CVE-2026-61825 and, for CVE-2026-61823, removes `srcdoc` from the permitted iframe attributes. As workarounds for applications unable to upgrade immediately, the vendor recommends sanitizing all editor content before storing or rendering it (for example using Symfony HtmlSanitizer), disabling RAW_HTML functionality where not required, and manually removing any iframe `srcdoc` attributes from stored Editor field content.

Recommended Action

Site owners and developers using code16/sharp should update to version 9.22.5 as soon as possible. If immediate upgrading is not feasible, apply the documented workarounds: sanitize all rich-text editor content server-side, disable RAW_HTML where it is not strictly necessary, and strip iframe `srcdoc` attributes from stored content.

PatchBriefing score

4.8 / 10 · Medium

Official CVSS: 8.7

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Why this score

CVE-2026-61825 scores 8.7 (CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N), reflecting network attack vector, low complexity, low privileges required, required user interaction, a changed scope, and high confidentiality and integrity impact with no availability impact. CVE-2026-61823 scores 7.3 (CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N), with the same attack characteristics but an unchanged scope. Neither vulnerability is listed as known exploited, has public exploit code, or has an available EPSS score reflected in the patchwire score, and both have vendor-supplied fixes available, which keeps the computed PatchBriefing scores at 4.8 and 4.0 respectively.

Affected versions

code16/sharp < 9.22.5
vulnerable
code16/sharp <9.22.5
vulnerable
≥ 9.22.5
patched
code16/sharp < 9.22.5
vulnerable
code16/sharp <9.22.5
vulnerable
≥ 9.22.5
patched

Reported fixes

The vendor has released version 9.22.5, which patches CVE-2026-61825 and, for CVE-2026-61823, removes `srcdoc` from the permitted iframe attributes. As workarounds for applications unable to upgrade immediately, the vendor recommends sanitizing all editor content before storing or rendering it (for example using Symfony HtmlSanitizer), disabling RAW_HTML functionality where not required, and manually removing any iframe `srcdoc` attributes from stored Editor field content.

How this was built

6 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
Two Stored XSS Vulnerabilities Patched in code16/Sharp Admin Framework
1 article · 6 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email