Description
A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
Published: 2026-09-09
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side cross‑site scripting via file upload
Action: Mitigate
AI Analysis

Impact

A stored cross‑site scripting (XSS) flaw exists in the H5P module "h5p-nodejs-library" that allows an attacker to upload H5P content containing malicious JavaScript. When another user views the compromised H5P content, the embedded script runs in their browser, potentially allowing the attacker to steal session cookies, deface pages, or conduct further phishing attacks. This flaw is based on improper input validation (CWE‑79) and unsafe handling of file extensions (CWE‑20).

Affected Systems

The vulnerability affects Lumi Education UG’s h5p-nodejs-library product in all versions up to and including 10.0.4. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 5.2 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to upload malicious content through the module’s file‑upload interface, which is then rendered to other users. Because the flaw relies on extension‑based filtering alone, an attacker can choose an allowed extension (e.g., XML) and embed harmful JavaScript, making the risk significant for sites that do not employ additional content validation. However, the impact is limited to client‑side execution and does not provide remote code execution on the server itself.

Generated by OpenCVE AI on September 9, 2026 at 10:21 UTC.

Remediation

Vendor Solution

At the time of publication, no release fully prevents the upload and execution of files that contain JavaScript. Version 10.0.4 removes the SVG file extension from the default content allowlist, but it still identifies permitted files by their filename extension alone. An attacker can therefore upload a file with malicious JavaScript content under an allowed extension, such as XML, and have it executed. Until a complete fix is available, operators should not rely on extension-based filtering alone. Uploaded files should be validated and sanitized based on their actual content rather than their filename. For SVG uploads specifically, the library's [SVG file sanitization](https://github.com/Lumieducation/H5P-Nodejs-library/blob/v10.0.4/docs/packages/h5p-svg-sanitizer.md) can be enabled, which uses DOMPurify to remove malicious script content from uploaded files.


OpenCVE Recommended Actions

  • Upgrade to the latest version of h5p-nodejs-library (at least v10.0.4) to remove the SVG file extension from the default allowlist.
  • Enable the library’s SVG sanitization feature, which uses DOMPurify to strip script content from uploaded files.
  • Implement server‑side validation that inspects the actual content of uploaded files rather than relying solely on file‑extension checks.

Generated by OpenCVE AI on September 9, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lumi Education Ug
Lumi Education Ug h5p-nodejs-library
Vendors & Products Lumi Education Ug
Lumi Education Ug h5p-nodejs-library

Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Education UG in versions up to and including 10.0.4. The library allows users to upload H5P content that contains malicious JavaScript. This code is then executed in the browsers of other users who view the affected H5P content.
Title Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
Weaknesses CWE-20
CWE-79
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:P'}


Subscriptions

Lumi Education Ug H5p-nodejs-library
cve-icon MITRE

Status: PUBLISHED

Assigner: SCHUTZWERK

Published:

Updated: 2026-09-22T19:06:34.604Z

Reserved: 2025-07-04T06:13:06.914Z

Link: CVE-2025-7062

cve-icon Vulnrichment

Updated: 2026-09-22T19:06:34.604Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T07:16:55.180

Modified: 2026-09-22T19:16:40.567

Link: CVE-2025-7062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:10:40Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')