Executive brief
Craft CMS, a popular content management system, is vulnerable to a security flaw where malicious code can be hidden within user group names. An administrator could use this to target other staff members, potentially stealing their session information or performing actions on their behalf when they view the user permissions page. This could lead to unauthorized changes to website content or administrative settings.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Craft CMS versions 5.0.0-RC1 through 5.8.21. The root cause is the failure to properly HTML-escape user group names when they are rendered on the individual User Permissions page (/admin/users/{id}). An attacker with administrative privileges can set a user group name to a malicious payload (e.g., using an <img> tag with an onerror attribute). When another user views or edits the permissions of a user belonging to that group, the payload executes in their browser session. This vulnerability is patched in version 5.8.22.
Affected products
- Pixel & Tonic Craft CMS >= 5.0.0-RC1, <= 5.8.21
Timeline
- 2026-03-09: advisory: Original advisory GHSA-g3hp-vvqf-8vw6 published
- 2026-06-21: disclosed: CVE-2026-56381 assigned and published
- 2026-08-06: patched: Duplicate advisory GHSA-9r7j-7jhg-4f4c withdrawn in favor of original report