Description
Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator's session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that can compromise an administrator’s session and enable cross‑privilege actions
Action: Patch Immediately
AI Analysis

Impact

Vendure’s dashboard component RichTextDescriptionCell strips markup by temporarily inserting an administrator‑controlled description into a live element’s innerHTML and then reading its textContent. During the innerHTML assignment, any event handler in the injected markup can execute, allowing a malicious administrator to embed scripts that run when another administrator later views the affected row. This stored cross‑site scripting attack can compromise the viewing administrator’s session cookie and permit cross‑privilege or cross‑channel administrative actions.

Affected Systems

Any instance of vendurehq:vendure with a version earlier than 3.6.5 is affected. The vulnerability can be triggered in the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, where lower‑privilege administrators can store malicious markup in entity descriptions.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, but the lack of a listed KEV suggests no confirmed exploits yet. An attacker must first create or edit an entity description using a lower‑privilege administrator account, then rely on a higher‑privilege administrator to trigger the stored script by viewing the list. Once triggered, the script can hijack the session, enabling privileged actions or further exploitation.

Generated by OpenCVE AI on September 17, 2026 at 20:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to vendure 3.6.5 or later to apply the vendor patch that removes the unsafe innerHTML usage
  • Audit the database for any existing descriptions containing embedded event handlers or inline scripts and delete or cleanse those entries
  • Implement input validation on future description fields to reject or escape HTML tags and prevent event handlers from being stored

Generated by OpenCVE AI on September 17, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xhq9-whgq-49j5 Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vendure
Vendure vendure
Vendors & Products Vendure
Vendure vendure

Thu, 17 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assignment before textContent is read. A lower-privilege administrator can store such markup in descriptions rendered by the Products list, Collections list, Promotions list, Payment Methods list, or Shipping Methods list, and script executes when another administrator views the affected row. This stored cross-site scripting can compromise the viewing administrator's session and enable cross-privilege or cross-channel administrative actions. This issue is fixed in version 3.6.5.
Title Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:46:16.224Z

Reserved: 2026-07-16T21:37:45.768Z

Link: CVE-2026-63459

cve-icon Vulnrichment

Updated: 2026-09-21T20:46:09.992Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:49.290

Modified: 2026-09-21T21:17:08.580

Link: CVE-2026-63459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')