Executive brief
A vulnerability in Craft CMS allows an attacker to execute malicious code in an administrator's browser session. By creating a GitHub issue with a specially crafted title, an attacker can trigger this code when an administrator searches for feedback within the Craft CMS dashboard. This could allow the attacker to perform actions on behalf of the administrator, potentially compromising the website's data or configuration.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the CraftSupport widget of Craft CMS. The root cause is the improper handling of GitHub API responses in `CraftSupportWidget.js`, where `result.title` is passed directly to jQuery's `.html()` method without sanitization. Because the GitHub API returns issue titles as raw strings, an attacker can submit a GitHub issue to the `craftcms/cms` repository containing a JavaScript payload (e.g., using `<img>` tags with `onerror` attributes). When an administrator uses the 'Give feedback' search and the malicious issue is returned, the payload executes in the context of the control panel. This allows for session hijacking or performing administrative actions via CSRF token access. The issue is fixed in versions 4.17.16 and 5.9.23.
Affected products
- Pixel & Tonic Craft CMS >= 4.0.0-RC1, < 4.17.15; >= 5.0.0-RC1, < 5.9.22
Timeline
- 2026-06-16: disclosed
- 2026-07-01: advisory: NVD published date
- 2026-07-06: patched: GitHub Advisory published/updated date