Impact
The vulnerability arises from the way plone.app.textfield handles RichText fields. When the stored MIME type exactly matches the desired output MIME type, even if the content claims to be text/x-html-safe, the system bypasses the safe_html sanitizer. This shortcut lets the raw stored value flow to the frontend via tal:content=structure without escaping. Attackers who can write to a RichText field can embed JavaScript that will execute in any browser that loads the page. This can occur either through a standard field configuration that sets identical mimeType and outputMimeType, or through the REST API by submitting content with a text/x-html-safe content type. The flaw was resolved in versions 2.0.2, 3.0.2, and 4.0.1.
Affected Systems
The vulnerability affects Plone installations that use plone.app.textfield on any release line before the following versions: 2.0.2 for the 2.x branch, 3.0.2 for the 3.x branch, and 4.0.1 for the 4.x branch.
Risk and Exploitability
The official CVSS score is 4.3, representing moderate severity. The EPSS score for this vulnerability is less than 1%, indicating a very low probability of widespread exploitation, and it is not listed in the CISA KEV catalog. An attacker can exploit the flaw by creating or editing a RichText field with a text/x-html-safe MIME type. The attack requires write access to the affected field and is client‑side, meaning the impact manifests when a user loads a compromised page. While the server side remains intact, the vulnerability can lead to client‑side script execution, potentially compromising user data or defacing page content. The risk remains moderate given the requirement for content modification access and the lack of a known exploit in the wild.
OpenCVE Enrichment
Github GHSA