CVE-2026-44990
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/06/2026
Last modified:
27/07/2026
Description
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
Impact
Base Score 3.x
9.30
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rpr9-rxv7-x643
- https://access.redhat.com/errata/RHSA-2026:36882
- https://access.redhat.com/errata/RHSA-2026:36883
- https://access.redhat.com/errata/RHSA-2026:40262
- https://access.redhat.com/errata/RHSA-2026:41031
- https://access.redhat.com/errata/RHSA-2026:41055
- https://access.redhat.com/errata/RHSA-2026:41064
- https://access.redhat.com/errata/RHSA-2026:41066
- https://access.redhat.com/errata/RHSA-2026:42146
- https://access.redhat.com/errata/RHSA-2026:42796
- https://access.redhat.com/errata/RHSA-2026:43052
- https://access.redhat.com/security/cve/CVE-2026-44990
- https://bugzilla.redhat.com/show_bug.cgi?id=2488565
- https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rpr9-rxv7-x643
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44990.json



