Executive brief
Decidim is an open-source participatory democracy platform used by governments and organizations to engage with citizens. A vulnerability in the platform's landing page editor allows administrators to embed malicious scripts that execute in the browsers of visitors. While this requires administrative access to exploit, it could be used by a compromised or malicious staff member to perform unauthorized actions on behalf of site visitors.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Decidim's content block system. The root cause is the use of the `.html_safe` method in `Decidim::ContentBlocks::HtmlCell#html_content` (and related cells like SummaryCell and SectionCell) which renders admin-supplied HTML without a sanitization boundary. An attacker with administrative privileges to edit landing pages can persist arbitrary JavaScript that executes in the context of any user visiting the affected page. The vulnerability has been addressed by replacing `.html_safe` with the `decidim_sanitize_editor_admin` helper to properly neutralize unsafe tags and attributes. Patches are available in versions 0.30.9, 0.31.5, and 0.32.0.
Affected products
- Decidim decidim-core < 0.30.9, >= 0.31.0.rc1, < 0.31.5, >= 0.32.0.rc1, < 0.32.0
Timeline
- 2026-03-23: other: Pull request with fix submitted
- 2026-05-07: patched: Fix merged into develop branch
- 2026-07-13: advisory: GitHub Advisory published