VDB
Sign up
HIGH7.1

GHSA-cc4g-m3g7-xmw8

Decidim has a cross-site scripting vulnerability in the version control page

Quick fix

GHSA-cc4g-m3g7-xmw8 — decidim: upgrade to the fixed version with the command below.

bundle update decidim

Details

### Impact

The version control feature used in resources is subject to potential cross-site scripting (XSS) attack through a malformed URL.

### Workarounds

Not available

### References

OWASP ASVS v4.0.3-5.1.3

### Credits

This issue was discovered in a security audit organized by [Open Source Politics](https://opensourcepolitics.eu/) against Decidim done during July 2025.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim
Introduced in: 0Fixed in: 0.27.8
Fixbundle update decidim

References