{"id":"GHSA-9mvp-w4rr-5c6x","summary":"decidim-elections: Election question titles allow stored script execution","details":"## Description\n\nA low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.\n\n## Technical description\n \nThis stored XSS appears because election question titles are rendered as trusted HTML instead of sanitized text. The election question editor stores `question.body` as a normal translatable string, and the public helper `question_title` returns that value with `html_safe` and no sanitization boundary, so any user who can edit election questions can persist markup or script-bearing payloads that later render on public election pages.\n\n\u003cimg width=\"1506\" height=\"1285\" alt=\"decidim-election-01\" src=\"https://github.com/user-attachments/assets/2e17f396-10f9-4423-bb97-5badbdb20d21\" /\u003e\n\u003cimg width=\"1540\" height=\"657\" alt=\"decidim-election-02\" src=\"https://github.com/user-attachments/assets/178adb7b-d00e-4b5d-9237-f391e523973f\" /\u003e\n\n### Impact\n\nA low-privilege process-scoped admin or other election editor with question-management rights can persist JavaScript that executes in visitor's browsers on public election pages and voting booth screens.\n\n### Patches\n\nSee https://github.com/decidim/decidim/pull/16659\n\n### Workarounds\n\nDevelopers should review their implementation's administrator accesses and not give access to untrustworthy users\n\n### Resources\n\nOWASP XSS Injection\n\n### Credits\n\nThis issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicallyopensecurity.com/) against Decidim financed by [NGI](https://ngi.eu/).","aliases":["CVE-2026-44282"],"modified":"2026-09-09T18:25:58.339496Z","published":"2026-09-09T17:59:52Z","database_specific":{"github_reviewed_at":"2026-09-09T17:59:52Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/decidim/decidim/security/advisories/GHSA-9mvp-w4rr-5c6x"},{"type":"WEB","url":"https://github.com/decidim/decidim/pull/16659"},{"type":"PACKAGE","url":"https://github.com/decidim/decidim"}],"affected":[{"package":{"name":"decidim-elections","ecosystem":"RubyGems","purl":"pkg:gem/decidim-elections"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.32.0"}]}],"versions":["0.22.0","0.23.0","0.23.1","0.23.1.rc1","0.23.2","0.23.3","0.23.4","0.23.5","0.23.6","0.24.0","0.24.0.rc1","0.24.0.rc2","0.24.1","0.24.2","0.24.3","0.25.0","0.25.0.rc1","0.25.0.rc2","0.25.0.rc3","0.25.0.rc4","0.25.1","0.25.2","0.26.0","0.26.0.rc1","0.26.0.rc2","0.26.1","0.26.10","0.26.2","0.26.3","0.26.4","0.26.5","0.26.7","0.26.8","0.26.9","0.27.0","0.27.0.rc1","0.27.0.rc2","0.27.1","0.27.10","0.27.2","0.27.3","0.27.4","0.27.5","0.27.6","0.27.7","0.27.8","0.27.9","0.28.0","0.28.0.rc4","0.28.0.rc5","0.28.1","0.28.2","0.28.3","0.28.4","0.28.5","0.28.6","0.31.0","0.31.0.rc1","0.31.0.rc2","0.31.1","0.31.2","0.31.3","0.31.4","0.31.5","0.31.6","0.31.7","0.32.0.rc1","0.32.0.rc2","0.32.0.rc3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9mvp-w4rr-5c6x/GHSA-9mvp-w4rr-5c6x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}