Executive brief
Stencil core is a compiler and runtime framework for building reusable web components distributed across web applications. A DOM-based cross-site scripting vulnerability in the component runtime allows attackers to inject and execute malicious JavaScript in the context of affected websites. The flaw occurs when applications use scoped components with experimental slot fixes enabled and write untrusted data to host element text content, which gets parsed as HTML instead of plain text.
Technical details
The vulnerability is a DOM-based XSS (CWE-79) in Stencil's runtime text-writing patch for scoped components. When the experimental slot-fixes option is enabled, the runtime's host element textContent property incorrectly parses assigned values as HTML fragments instead of treating them as plain text, allowing HTML markup and event attributes to be processed. An attacker can exploit this by providing crafted input to textContent properties of scoped host elements, resulting in arbitrary script execution in the application's origin without requiring authentication or user interaction beyond normal page interaction.
Affected products
- Stencil core 4.43.5, 4.45.0, and likely other recent versions
Timeline
- 2026-09-21: disclosed
- 2026-08-04: other: Report date