highVulnerability

CVE-2026-55790

## Summary An attacker with only a GitHub account can plant a JavaScript payload in a `craftcms/cms` issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the payload executes in the admin’s control panel session. No control panel account or elevated privileges are required on the attacker’s side. ## Preconditions - Attacker has a GitHub account (no control panel access needed). - Victim is an administrator, and you have the CraftSupport widget on the dashboard. - Victim uses the "Give feedback" screen and types a search term that returns the poisoned issue. ## Root cause `CraftSupportWidget.js` lines 382-392: ```js $('<a>', { href: this.getSearchResultUrl(results[i]), target: '_blank', html: '<span class="status ' + this.getSearchResultStatus(results[i]) + '"></span>' + this.getSearchResultText(results[i]), }) ``` `FeedbackScreen.getSearchResultText` (line 669-671) returns `result.title` verbatim from the GitHub API response. The jQuery `html:` option sets the element’s `innerHTML`, so a title containing `<img src=x onerror=...>` executes immediately on render. The GitHub API returns issue titles as raw JSON strings with no HTML encoding. The widget makes this request directly from the browser, without a Craft proxy or any sanitization step. `HelpScreen` (Stack Exchange) is not affected because the Stack Exchange API HTML-encodes titles before returning them. ## Steps to reproduce **Plant (attacker, GitHub account only):** 1. Open `https://github.com/craftcms/cms/issues/new`. 2. Set the title to a string combining a plausible search term and the payload, e.g.: ``` <img src=x onerror=alert(document.domain)> cannot upload files ``` 3. Submit the issue. **Trigger (victim, Craft admin):** 1. Open the Craft control panel dashboard. 2. Open the CraftSupport widget, click "Give feedback". 3. Type `cannot upload files` in the search box. 4. `alert

Properties

ghsa_id
GHSA-24x4-j6x9-rfw5
severity
high
summary
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
epss_score
0.00311
cve_id
CVE-2026-55790
is_ghsa_only
false
ghsa_published
2026-07-06T21:29:16Z
source_url
https://github.com/advisories/GHSA-24x4-j6x9-rfw5
epss_percentile
0.23897
ghsa_updated
2026-07-06T21:29:17Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]composer/craftcms/cms

AFFECTS (1)

[Software]composer/craftcms/cms

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55790 — Ninja Signal Threat Intelligence | Ninja Signal