Junglewise Threat Intelligence

Sveltia CMS stored XSS in Markdown preview via unsandboxed iframe

Severity: medium · CVSS 4 · Published 2026-06-19

Technologies: Sveltia CMS, @sveltia/cms (npm). Vendors: npm.

Executive brief

Sveltia CMS is a headless content management system used by developers and small teams to manage website and application content. A stored cross-site scripting vulnerability in the Markdown/RichText preview feature allows an attacker who can modify content in the repository to inject malicious HTML code that executes in the CMS editor's browser, potentially exposing or manipulating editor data and sessions. The practical risk is limited because Sveltia CMS is designed for single-developer or small trusted teams, not untrusted multi-user environments.

Technical details

Sveltia CMS's Markdown/RichText field preview renderer uses DOMPurify for HTML sanitization but configured DOMPurify to permit iframe elements without enforcing sandbox attributes or restricting sources. When sanitized Markdown output is inserted into the preview DOM as raw HTML, an attacker can craft a Markdown field containing an iframe with src pointing to a same-origin URL (e.g., an uploaded HTML asset). The unsandboxed iframe executes with the parent CMS window's origin, allowing JavaScript access to the parent's state, DOM, storage, and CMS actions via same-origin policy. Exploitation requires the ability to write malicious content to the repository or content source that the CMS loads. The patch implements a two-pass sanitization pipeline: DOMPurify runs first, then a post-processing step removes any iframe elements using non-HTTPS schemes, same-origin URLs, or relative paths, with surviving HTTPS cross-origin iframes sandboxed. Fix: upgrade to Sveltia CMS v0.167.3 or later.

Affected products

  • Sveltia CMS 0.167.2 and earlier

Timeline

  • 2026-06-19: disclosed: GHSA-h5jc-78hr-3pc9 published
  • 2026-06-19: patched: Patch released in v0.167.3

References

Related threats