ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:36882 cve-icon
https://access.redhat.com/errata/RHSA-2026:36883 cve-icon
https://access.redhat.com/errata/RHSA-2026:40262 cve-icon
https://access.redhat.com/errata/RHSA-2026:41031 cve-icon
https://access.redhat.com/errata/RHSA-2026:41055 cve-icon
https://access.redhat.com/errata/RHSA-2026:41064 cve-icon
https://access.redhat.com/errata/RHSA-2026:41066 cve-icon
https://access.redhat.com/errata/RHSA-2026:42146 cve-icon
https://access.redhat.com/errata/RHSA-2026:42796 cve-icon
https://access.redhat.com/errata/RHSA-2026:43052 cve-icon
https://access.redhat.com/errata/RHSA-2026:46598 cve-icon
https://access.redhat.com/errata/RHSA-2026:46685 cve-icon
https://access.redhat.com/errata/RHSA-2026:46885 cve-icon
https://access.redhat.com/errata/RHSA-2026:46903 cve-icon
https://access.redhat.com/errata/RHSA-2026:47735 cve-icon
https://access.redhat.com/errata/RHSA-2026:47737 cve-icon
https://access.redhat.com/errata/RHSA-2026:48124 cve-icon
https://access.redhat.com/errata/RHSA-2026:51196 cve-icon
https://access.redhat.com/errata/RHSA-2026:51197 cve-icon
https://access.redhat.com/errata/RHSA-2026:51349 cve-icon
https://access.redhat.com/errata/RHSA-2026:57191 cve-icon
https://access.redhat.com/errata/RHSA-2026:57194 cve-icon
https://access.redhat.com/errata/RHSA-2026:59593 cve-icon
https://access.redhat.com/errata/RHSA-2026:60386 cve-icon
https://access.redhat.com/errata/RHSA-2026:60441 cve-icon
https://access.redhat.com/errata/RHSA-2026:63046 cve-icon
https://access.redhat.com/errata/RHSA-2026:63103 cve-icon
https://access.redhat.com/security/cve/CVE-2026-44990 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2488565 cve-icon
https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-rpr9-rxv7-x643 cve-icon cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-44990 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44990.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-44990 cve-icon
History

Wed, 09 Sep 2026 13:30:00 +0000


Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
References

Thu, 20 Aug 2026 13:30:00 +0000


Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 15 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Apostrophecms
Apostrophecms sanitize-html
Vendors & Products Apostrophecms
Apostrophecms sanitize-html

Fri, 12 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.
Title Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-06-12T20:39:47.065Z

Updated: 2026-09-10T12:05:09.696Z

Reserved: 2026-05-08T16:23:33.265Z

Link: CVE-2026-44990

cve-icon Vulnrichment

Updated: 2026-09-10T12:05:09.696Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T21:16:22.447

Modified: 2026-09-10T13:20:17.020

Link: CVE-2026-44990

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-12T20:39:47Z

Links: CVE-2026-44990 - Bugzilla