Executive brief
CKAN is an open-source data management platform used by organizations to publish and share datasets. The helpers.markdown_extract() function fails to properly sanitize user-supplied text before rendering it as HTML, allowing attackers with login credentials to inject malicious scripts into resource descriptions. When other users view these pages, the injected code executes in their browsers, potentially stealing session tokens or sensitive data.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the helpers.markdown_extract() function, which processes markdown input and wraps it in HTML without sufficient output encoding. The vulnerability affects dataset, resource, organization, and group pages, as well as any extension using this helper. An authenticated attacker can inject JavaScript payload into description fields; when a victim visits the page, the script executes in their browser context with their privileges. The vulnerability requires authentication and user interaction (victim viewing the page). Patches are available in CKAN 2.10.9 and 2.11.4.
Affected products
- CKAN CKAN before 2.10.9 and before 2.11.4
Timeline
- 2025-10-29: disclosed
- 2025-10-29: patched: Fixed in CKAN 2.10.9 and 2.11.4