Sanitizer Bypass Vulnerability in ApostropheCMS by Apostrophe, Affecting sanitize-html
CVE-2026-44990
9.3CRITICAL
What is CVE-2026-44990?
ApostropheCMS, paired with the sanitize-html library, contains a flaw that allows attackers to exploit the content management system. Undesirable content within a disallowed xmp element can be transformed into executable HTML or JavaScript by certain versions of sanitize-html, specifically those before 2.17.4. This vulnerability occurs due to a sanitizer bypass in the default disallowedTagsMode: 'discard', posing a risk of stored cross-site scripting (XSS) in setups where the sanitized output is rendered visually without adequate filtering. Version 2.17.4 has been released to address this issue.
Affected Version(s)
sanitize-html < 2.17.4
