Junglewise Threat Intelligence

CVE-2024-27091: GeoNode stored XSS in rich text editor

CVE-2024-27091 · Severity: medium · CVSS 6.1 · Published 2026-07-13

Technologies: Geonode, geonode (PyPI). Vendors: PyPI.

Executive brief

GeoNode, a platform for sharing geospatial data, contains a security flaw in its text editor. An attacker can use this to run malicious scripts in another user's browser, potentially allowing them to hijack accounts by changing the associated email address. This could lead to a total loss of control over user accounts and the data they manage.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the GeoNode rich text editor due to improper neutralization of user-controllable input (CWE-79). Although application cookies are set with secure flags, an attacker can inject malicious scripts that, when viewed by a victim, retrieve the victim's CSRF token. The attacker can then use this token to issue an unauthorized request to change the victim's email address, leading to a full account takeover. The exploit is successful because script elements do not trigger CORS policy restrictions in this context. The issue is fixed in version 4.2.3.

Affected products

  • GeoNode GeoNode >= 3.2.1, < 4.2.3

Timeline

  • 2024-03-27: disclosed: Initial disclosure and NVD publication
  • 2024-03-27: patched: Fix committed to repository
  • 2026-07-13: advisory: GitHub Advisory published/updated

References

Related threats