Feed/CVE-2026-54503
CVE-2026-54503MEDIUMCVSS 4.3

plone.app.textfield: Stored XSS by spoofing mime type

Published Jul 17, 2026·Updated Jul 17, 2026

NVD Description

### Impact A stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (`text/x-html-safe`) is the type that signifies "already sanitized", any value whose stored mimeType equals it bypasses the safe_html transform entirely on render. The transform itself is sound — it correctly strips `on*` event-handler attributes and `javascript:/data:` URIs; the defect is that it is never invoked for these values. The unsanitized value is then emitted via `tal:content="structure ..."`, which performs no escaping, so the payload executes in the viewer's browser. This can be a problem when a RichText field is wrongly defined in code with a `mimeType` and `outputMimeType` that are the same, or when the REST API is used to the same effect. ### Patches The problem has been patched: * For Plone 6.0, upgrade `plone.app.textfield` to 2.0.2. * For Plone 6.1, upgrade `plone.app.textfield` to 3.0.2. * For Plone 6.2, upgrade `plone.app.textfield` to 4.0.1. ### Workarounds There is no known workaround.

Affected Packages (1)

plone.app.textfieldPYPI
Fixed in 2.0.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free