GHSA-9mvp-w4rr-5c6x
decidim-elections: Election question titles allow stored script execution
Quick fix
GHSA-9mvp-w4rr-5c6x — decidim-elections: upgrade to the fixed version with the command below.
bundle update decidim-electionsDetails
## Description
A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.
## Technical description This stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores `question.body` as a normal translatable string, and the public helper `question_title` returns that value with `html_safe` and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.
<img width="1506" height="1285" alt="decidim-election-01" src="https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21" /> <img width="1540" height="657" alt="decidim-election-02" src="https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f" />
### Impact
A low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.
### Patches
See https://github.com/decidim/decidim/pull/16659
### Workarounds
Developers should review their implementation's administrator accesses and not give access to untrustworthy users
### Resources
OWASP XSS Injection
### Credits
This issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicallyopensecurity.com/) against Decidim financed by [NGI](https://ngi.eu/).
Are you affected?
Enter the version of the package you're using.