CVE-2026-44990

Aliases:GHSA-rpr9-rxv7-x643
Advisory lineage Upstream: 0 Downstream: 1
Deferred
Published: 12 Jun 2026, 20:39
Last modified:10 Sept 2026, 12:05

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 CRITICAL
v3.1 (cve.org)
EPSS Score
0.6% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Jun 2026, 20:39
Published
Vulnerability first disclosed
10 Sept 2026, 12:05
Last Modified
Vulnerability information updated

Description

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

CVSS Metrics

  • v3.1CRITICALScore: 9.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.60% Percentile: 47%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • apostrophecmssanitize-html

    < 2.17.4

  • Npmsanitize-html

    ≤ 2.17.3 | ≥ 2.17.3, < 2.17.4

References (37)