Executive brief
Omeka S is a web publication platform used by museums, libraries, and archives to organize and share digital collections. A cross-site scripting vulnerability in the site navigation custom URL function allows remote attackers to inject malicious scripts that execute in visitors' browsers, potentially stealing session tokens, redirecting users to phishing sites, or defacing the site's appearance.
Technical details
A cross-site scripting (XSS) vulnerability exists in the site navigation link URL validation in Omeka S v.4.2.0. The vulnerable component (application/src/Site/Navigation/Link/Url.php) fails to properly sanitize or validate user-supplied URLs before storing and rendering them in navigation menus. An attacker can inject JavaScript URLs (e.g., javascript:alert(...)) or HTML event handlers into custom navigation links. The vulnerability is network-reachable and requires authentication to add or modify navigation settings, though the injected script executes for any unauthenticated visitor viewing the affected page. The fix involves blocking URLs with the "javascript" scheme and likely improving overall URL validation and output encoding.
Affected products
- Omeka Omeka S 4.2.0
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: GitHub commit 8d47b0e adds validation to block javascript: scheme in navigation URLs