Junglewise Threat Intelligence

CVE-2026-31859: CraftCMS reflected XSS via incomplete return URL sanitization

CVE-2026-31859 · Severity: medium · CVSS 4 · Published 2026-03-11

Technologies: CraftCMS CMS.

Executive brief

CraftCMS, a popular content management system, is vulnerable to a security flaw where it fails to properly check redirect links. An attacker could send a malicious link to a user that, when clicked, executes unauthorized code in their browser. This could lead to the theft of login sessions, sensitive data exposure, or redirecting users to fraudulent websites.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in CraftCMS due to incomplete sanitization of return URLs in `src/web/User.php`. While the application uses `strip_tags()` to remove HTML elements, it fails to validate URL schemes. Attackers can bypass this check using `javascript:`, `data:`, or protocol-relative URIs, which do not contain HTML tags. When these unsanitized URLs are rendered within an `href` attribute, clicking the link executes the attacker's payload. This can result in session hijacking, CSRF, or data exfiltration. Patches are available in versions 4.17.3 and 5.9.7.

Affected products

  • CraftCMS cms >= 4.15.3, <= 4.17.2
  • CraftCMS cms >= 5.7.5, <= 5.9.6

Timeline

  • 2026-03-09: patched: Fix released in versions 4.17.3 and 5.9.7
  • 2026-03-11: advisory: GitHub Advisory GHSA-fvwq-45qv-xvhv published

References