Threat Advisory

Plone.app.textfield Stored XSS via Spoofed Mime Type

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability, identified as CVE-2026-54503 with a CVSS v3 score of 4.3 , affects RichText fields in plone.app.textfield. This flaw type is categorized under CWE-80 and can be exploited via a crafted RichText field with a specific mimeType and outputMimeType combination, resulting in the execution of arbitrary code in the viewer's browser. The attack vector is network-based (AV:N) and requires low privileges (PR:L). The business impact is significant, as an attacker could potentially inject malicious JavaScript into the application, leading to unauthorized access or data tampering. Affected versions include plone.app.textfield prior to 2.0.2, between 3.0.0 and 3.0.2, and exactly version 4.0.0. The vulnerability can occur when a RichText field is wrongly defined in code with a mimeType and outputMimeType that are the same or when the REST API is used to the same effect, bypassing the safe_html transform and allowing unsanitized values to be emitted via tal:content="structure...".

RECOMMENDATION:

We recommend you to upgrade plone.app.textfield to version 2.0.2, 3.0.2, or 4.0.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A stored cross-site scripting vulnerability, identified as CVE-2026-54503 with a CVSS v3 score of 4.3 , affects RichText fields in plone.app.textfield. This flaw type is categorized under CWE-80 and can be exploited via a crafted RichText field with a specific mimeType and outputMimeType combination, resulting in the execution of arbitrary code in the viewer's browser. The attack vector is network-based (AV:N) and requires low privileges (PR:L). The business impact is significant, as an attacker could potentially inject malicious JavaScript into the application, leading to unauthorized access or data tampering. Affected versions include plone.app.textfield prior to 2.0.2, between 3.0.0 and 3.0.2, and exactly version 4.0.0. The vulnerability can occur when a RichText field is wrongly defined in code with a mimeType and outputMimeType that are the same or when the REST API is used to the same effect, bypassing the safe_html transform and allowing unsanitized values to be emitted via tal:content="structure...".

RECOMMENDATION:

We recommend you to upgrade plone.app.textfield to version 2.0.2, 3.0.2, or 4.0.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu