Medium · 4.8 PHP packages GHSA-vj3q-vp3g-j9c8 CVE-2026-61825 PKSA-p6zx-3z97-z7f8 GHSA-qxg3-46rw-79j8
Two Stored XSS Vulnerabilities Patched in code16/Sharp Admin Framework
Sharp, a Laravel-based CMS/admin framework, fixed two stored cross-site scripting vulnerabilities in its rich-text editor component. Both are resolved in version 9.22.5.
AI summary
code16 Sharp, a Laravel-based framework used to build content-management and administrative interfaces, has received a security update addressing two separate stored cross-site scripting (XSS) vulnerabilities in its rich-text editor functionality. Both issues affect versions of Sharp prior to 9.22.5 and have been resolved in that release. Neither vulnerability is currently known to be exploited in the wild, and no public exploit code has been reported.
What Happened
Two stored XSS vulnerabilities were disclosed in code16/Sharp's `SharpEditorFormField` rich-text editor component. CVE-2026-61825 involves attacker-controlled content bearing a `data-html-content` attribute bypassing HTML sanitization, allowing executable markup to persist and run when another user views the stored content. CVE-2026-61823 involves the HTML sanitizer permitting the `srcdoc` attribute on iframe elements; although the markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, which allows an authenticated user with Editor field permissions to store JavaScript that executes when another user views the content.
Technical Cause
Both vulnerabilities are classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). CVE-2026-61825 stems from a sanitizer bypass specific to the `data-html-content` attribute, which can preserve executable markup despite sanitization. CVE-2026-61823 stems from the sanitizer's allowlist permitting the `srcdoc` attribute on iframes; browsers decode HTML entities within that attribute before rendering it as a document, defeating the encoding-based mitigation.
Why It Matters
CVE-2026-61825 carries a CVSS score of 8.7, reflecting a scope-changed impact (the vulnerability can affect resources beyond the vulnerable component itself) with high confidentiality and integrity impact. CVE-2026-61823 carries a CVSS score of 7.3, also with high confidentiality and integrity impact, but without a scope change. The advisory for CVE-2026-61823 notes that successful exploitation could lead to session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data when a victim with elevated access views the stored malicious content.
Who Is Affected
Any application using code16/sharp versions before 9.22.5 that relies on the rich-text editor's `SharpEditorFormField` component is affected. This includes applications that intentionally enable `SharpFormEditorField::RAW_HTML`, which the vendor notes must continue to sanitize editor content independently even after patching.
Affected Versions
code16/sharp versions prior to 9.22.5 are affected by both vulnerabilities. Version 9.22.5 contains the fix for both CVE-2026-61825 and CVE-2026-61823.
Fixes and Mitigation
The vendor has released version 9.22.5, which patches CVE-2026-61825 and, for CVE-2026-61823, removes `srcdoc` from the permitted iframe attributes. As workarounds for applications unable to upgrade immediately, the vendor recommends sanitizing all editor content before storing or rendering it (for example using Symfony HtmlSanitizer), disabling RAW_HTML functionality where not required, and manually removing any iframe `srcdoc` attributes from stored Editor field content.
Recommended Action
Site owners and developers using code16/sharp should update to version 9.22.5 as soon as possible. If immediate upgrading is not feasible, apply the documented workarounds: sanitize all rich-text editor content server-side, disable RAW_HTML where it is not strictly necessary, and strip iframe `srcdoc` attributes from stored content.
PatchBriefing score
4.8 / 10 · Medium
Official CVSS: 8.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Why this score
CVE-2026-61825 scores 8.7 (CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N), reflecting network attack vector, low complexity, low privileges required, required user interaction, a changed scope, and high confidentiality and integrity impact with no availability impact. CVE-2026-61823 scores 7.3 (CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N), with the same attack characteristics but an unchanged scope. Neither vulnerability is listed as known exploited, has public exploit code, or has an available EPSS score reflected in the patchwire score, and both have vendor-supplied fixes available, which keeps the computed PatchBriefing scores at 4.8 and 4.0 respectively.
Affected versions
- code16/sharp < 9.22.5
- vulnerable
- code16/sharp <9.22.5
- vulnerable
- ≥ 9.22.5
- patched
- code16/sharp < 9.22.5
- vulnerable
- code16/sharp <9.22.5
- vulnerable
- ≥ 9.22.5
- patched
Reported fixes
The vendor has released version 9.22.5, which patches CVE-2026-61825 and, for CVE-2026-61823, removes `srcdoc` from the permitted iframe attributes. As workarounds for applications unable to upgrade immediately, the vendor recommends sanitizing all editor content before storing or rendering it (for example using Symfony HtmlSanitizer), disabling RAW_HTML functionality where not required, and manually removing any iframe `srcdoc` attributes from stored Editor field content.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email