CVE-2026-23499 affects Saleor e-commerce platform versions 3.0.0 through 3.20.107, 3.21.42, and 3.22.26, allowing authenticated staff or Apps to upload malicious HTML/SVG files. This medium-severity vulnerability (CVSS 5.4) enables cross-site scripting (XSS) if media files are hosted on the same domain as the dashboard and lack proper Content-Disposition headers, potentially leading to staff token theft. While not actively exploited or on the KEV catalog, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation. Patches are available in versions 3.22.27, 3.21.43, and 3.20.108, with workarounds including configuring Content-Disposition headers, preventing HTML/SVG serving, or implementing a strict Content-Security-Policy.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.20.108CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.21.0, < 3.21.43CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.22.0, < 3.22.27CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.