HIGH7.1
GHSA-cc4g-m3g7-xmw8
Decidim has a cross-site scripting vulnerability in the version control page
Quick fix
GHSA-cc4g-m3g7-xmw8 — decidim: upgrade to the fixed version with the command below.
bundle update decidimDetails
### Impact
The version control feature used in resources is subject to potential cross-site scripting (XSS) attack through a malformed URL.
### Workarounds
Not available
### References
OWASP ASVS v4.0.3-5.1.3
### Credits
This issue was discovered in a security audit organized by [Open Source Politics](https://opensourcepolitics.eu/) against Decidim done during July 2025.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-41673[ADVISORY]
- https://github.com/decidim/decidim/commit/8a18c8b1ee85a1b35ee0d8d5893f218695d15637[WEB]
- https://github.com/decidim/decidim[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim/CVE-2024-41673.yml[WEB]