Executive brief
Decap CMS is a headless CMS platform used to manage content for static site generators. An attacker with low-privilege author/contributor access can inject malicious JavaScript into content fields (title, description, tags, body) that executes when reviewers or maintainers preview the content in the admin interface. This enables session theft, credential harvesting, or unauthorized admin actions performed in the attacker's context.
Technical details
This is a stored cross-site scripting (XSS) vulnerability (CWE-79) affecting Decap CMS through version 3.8.3. The vulnerability exists in the admin preview pane, where user-controlled content fields are rendered without proper HTML sanitization or output encoding. An attacker with author/contributor privileges can persist a JavaScript payload in the CMS database; when an administrator or reviewer opens the preview functionality, the payload executes in the browser with the CMS admin's privileges and origin, enabling session token theft or DOM-based privilege escalation. The attack requires only passive user interaction (opening a preview). As of publication, no patched version is available; mitigation includes restricting contributor roles and disabling or filtering HTML preview rendering.
Affected products
- Decap CMS through 3.8.3
Timeline
- 2025-09-10: disclosed
- other: CVE-2025-57520 assigned