Executive brief
Tryton sao is the web client for the Tryton ERP system. The application improperly handles HTML attachments by executing embedded JavaScript code with full access to the user's session context. An authenticated user can upload malicious HTML attachments to steal session tokens and sensitive data, or perform unauthorized actions on behalf of the victim.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in how sao renders HTML documents, such as attachments. The application fails to sanitize or isolate JavaScript embedded in HTML attachments, executing it in the same security context as the web client. This allows authenticated users to upload malicious HTML files that execute arbitrary JavaScript with access to session cookies and sensitive data. The attack requires user interaction (opening the attachment) and user authentication. The issue has been fixed in sao versions 7.6.9, 7.4.19, 7.0.38, and 6.0.67. When inbound_email or document_incoming modules are enabled, the attack surface expands to include unauthenticated attackers sending emails with malicious attachments.
Affected products
- Tryton sao before 7.6.9, 7.4.x before 7.4.19, 7.0.x before 7.0.38, 6.0.x before 6.0.67
Timeline
- 2025-10-21: disclosed: Security advisory published by Tryton
- 2025-10-21: patched: Patches released in versions 7.6.9, 7.4.19, 7.0.38, and 6.0.67
- 2025-11-30: advisory: GHSA-xhgv-99mj-8m2x published