{"id":"CVE-2026-59167","summary":"SunEditor: Critical XSS vulnerability - sanitizer bypass","details":"SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.","aliases":["GHSA-6rf4-v2fh-m6p4"],"modified":"2026-09-24T03:46:32.354428601Z","published":"2026-09-23T13:52:56.747Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59167.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59167.json"},{"type":"FIX","url":"https://github.com/JiHong88/suneditor/commit/a94ace269c7102bfb6de58a27a6547bc4eb09045"},{"type":"REPORT","url":"https://github.com/JiHong88/suneditor/issues/1646"},{"type":"WEB","url":"https://github.com/JiHong88/suneditor/releases/tag/2.47.11"},{"type":"ADVISORY","url":"https://github.com/JiHong88/suneditor/security/advisories/GHSA-6rf4-v2fh-m6p4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59167"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jihong88/suneditor","events":[{"introduced":"0"},{"fixed":"7fd007adb7c0504a4c63cfbb74f17a667fab58b3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.47.11"}],"source":"AFFECTED_FIELD"}}],"versions":["2.47.10","2.47.9","2.47.8","2.47.7","2.47.6","2.47.5","2.47.1","2.47.0","2.46.3","2.46.2","2.46.1","2.46.0","2.45.1","2.45.0","2.44.12","2.44.10","2.44.9","2.44.8","2.44.7","2.44.6","2.44.5","2.44.4","2.44.3","2.44.2","2.44.1","2.44.0","2.43.14","2.43.11","2.43.10","2.43.9","2.43.8","2.43.6","2.43.5","2.43.4","2.43.3","2.43.0","2.42.0","2.41.3","2.41.2","2.41.1","2.41.0","2.40.0","2.39.0","2.38.10","2.38.8","2.38.7","2.38.6","2.38.5","2.38.4","2.38.3","2.38.2","2.38.1","2.38.0","2.37.4","2.37.3","2.37.2","2.37.1","2.37.0","2.36.5","2.36.4","2.36.2","2.36.1","2.36.0","2.35.1","2.35.0","2.34.3","2.34.2","2.34.1","2.34.0","2.33.3","2.33.1","2.33.0","2.32.1","2.32.0","2.31.2","2.31.1","2.31.0","2.30.7","2.30.6","2.30.5","2.30.4","2.30.1","2.30.0","2.29.0","2.28.4","2.28.3","2.28.2","2.28.1","2.28.0","2.27.1","2.27.0","2.26.0","2.25.0","2.24.0","2.23.4","2.23.3","2.22.0","2.21.2","2.21.1","2.21.0","2.20.1","2.19.1","2.18.0","2.17.3","2.17.2","2.16.3","2.16.2","2.16.1","2.15.3","2.15.2","2.14.0","2.13.1","2.12.4","2.12.3","2.12.0","2.11.1","2.10.2","2.9.6","2.9.5","2.9.4","2.9.2","2.8.5","2.8.0","2.7.1","2.6.3","2.5.3","2.4.3","2.4.2","2.4.1","2.3.0","2.2.7","2.2.6","2.2.4","2.2.2","2.1.1","2.0.15","2.0.13","2.0.11","1.11.4","1.11.0","1.10.4","1.10.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59167.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}