OVERVIEW CVE-2026-40186 is a cross-site scripting (XSS) vulnerability in the sanitize-html package versions 2.17.1 and earlier, which affects ApostropheCMS 4.28.0 through its dependency chain. A regression introduced in commit 49d0bb7 causes the sanitizer to incorrectly handle entity-encoded HTML within textarea and option elements. The vulnerability allows attackers to bypass the allowedTags filter by exploiting an incorrect assumption about how htmlparser2 10.x processes entity decoding, resulting in arbitrary HTML injection. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.1 (MEDIUM) with a network-based attack vector requiring no privileges but necessitating user interaction. Attack complexity is low, meaning exploitation requires minimal effort. The impact includes low-level confidentiality and integrity compromises through XSS payload injection, though no availability impact is present. The vulnerability is particularly concerning in non-default configurations where option or textarea elements are included in allowedTags, common in form builders and content management platforms. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, with the EPSS score of 0.0001 indicating minimal probability of exploitation. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and is classified as inactive on threat intelligence hotlists. However, patches are available in sanitize-html version 2.17.2 and ApostropheCMS 4.29.0, and organizations should prioritize updates to remediate this preventable risk vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.29.0CPE matchmatch criteria | cpe:2.3:a:apostrophecms:apostrophecms:4.29.0:*:*:*:*:*:*:* | ||
<= 2.17.1CPE matchmatch criteria | cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.