Description
plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim the text/x-html-safe output type. This equality shortcut bypasses the safe_html transform even though the transform itself correctly removes event-handler attributes and unsafe URI schemes. Equal types can result from a RichText field configured with the same mimeType and outputMimeType or from REST API input that supplies text/x-html-safe as its content type. The raw stored value is then emitted through tal:content=structure without escaping, allowing a user who can set a RichText field to store JavaScript that executes in a viewer's browser. This issue is fixed in versions 2.0.2, 3.0.2, and 4.0.1.
Published: 2026-09-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross-site scripting via MIME type manipulation
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the way plone.app.textfield handles RichText fields. When the stored MIME type exactly matches the desired output MIME type, even if the content claims to be text/x-html-safe, the system bypasses the safe_html sanitizer. This shortcut lets the raw stored value flow to the frontend via tal:content=structure without escaping. Attackers who can write to a RichText field can embed JavaScript that will execute in any browser that loads the page. This can occur either through a standard field configuration that sets identical mimeType and outputMimeType, or through the REST API by submitting content with a text/x-html-safe content type. The flaw was resolved in versions 2.0.2, 3.0.2, and 4.0.1.

Affected Systems

The vulnerability affects Plone installations that use plone.app.textfield on any release line before the following versions: 2.0.2 for the 2.x branch, 3.0.2 for the 3.x branch, and 4.0.1 for the 4.x branch.

Risk and Exploitability

The official CVSS score is 4.3, representing moderate severity. The EPSS score for this vulnerability is less than 1%, indicating a very low probability of widespread exploitation, and it is not listed in the CISA KEV catalog. An attacker can exploit the flaw by creating or editing a RichText field with a text/x-html-safe MIME type. The attack requires write access to the affected field and is client‑side, meaning the impact manifests when a user loads a compromised page. While the server side remains intact, the vulnerability can lead to client‑side script execution, potentially compromising user data or defacing page content. The risk remains moderate given the requirement for content modification access and the lack of a known exploit in the wild.

Generated by OpenCVE AI on September 20, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade plone.app.textfield to version 2.0.2, 3.0.2, or 4.0.1 or later
  • Restrict edit permissions for RichText fields to trusted users only
  • Audit configuration to ensure MIME types such as text/x-html-safe are not used as output types and enforce strict sanitization
  • As an interim measure, configure Plone to block or strip JavaScript from RichText content

Generated by OpenCVE AI on September 20, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4r4f-gg25-rmg5 plone.app.textfield: Stored XSS by spoofing mime type
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Plone
Plone plone.app.textfield
Vendors & Products Plone
Plone plone.app.textfield

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim the text/x-html-safe output type. This equality shortcut bypasses the safe_html transform even though the transform itself correctly removes event-handler attributes and unsafe URI schemes. Equal types can result from a RichText field configured with the same mimeType and outputMimeType or from REST API input that supplies text/x-html-safe as its content type. The raw stored value is then emitted through tal:content=structure without escaping, allowing a user who can set a RichText field to store JavaScript that executes in a viewer's browser. This issue is fixed in versions 2.0.2, 3.0.2, and 4.0.1.
Title plone.app.textfield: Stored XSS by spoofing mime type
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Plone Plone.app.textfield
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:02:18.109Z

Reserved: 2026-06-15T18:01:15.512Z

Link: CVE-2026-54503

cve-icon Vulnrichment

Updated: 2026-09-15T19:02:13.197Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T17:17:21.060

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-54503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)