Junglewise Threat Intelligence

Plone plone.restapi stored XSS via MIME type spoofing

Severity: medium · CVSS 4.3 · Published 2026-07-17

Vendors: Plone.

Executive brief

A vulnerability in the Plone REST API allows users to bypass security filters when saving rich text content. By mislabeling the type of data being sent, an attacker can store malicious scripts that execute in the browsers of other users who view the content. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored XSS vulnerability exists in plone.restapi's handling of RichText fields. The root cause is a logic error in RichTextValue.output where the safe-HTML transform is bypassed if the stored mimeType is set to 'text/x-html-safe' (the type indicating content is already sanitized). An attacker with permissions to edit content via the REST API can spoof this MIME type to store unsanitized HTML containing malicious scripts. When the content is rendered using 'tal:content="structure ..."', it is emitted without further escaping, leading to script execution in the viewer's browser. Patches are available in versions 9.15.6 and 10.0.1.

Affected products

  • Plone plone.restapi < 9.15.6, 10.0.0

Timeline

  • 2026-06-05: disclosed
  • 2026-07-17: advisory

References