CVE-2026-59167

Source
https://cve.org/CVERecord?id=CVE-2026-59167
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59167.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-59167
Aliases
Published
2026-09-23T13:52:56Z
Modified
2026-09-24T03:46:32Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
SunEditor: Critical XSS vulnerability - sanitizer bypass
Details

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59167.json"
}
References

Affected packages

Git / github.com/jihong88/suneditor

Affected ranges

Type
GIT
Repo
https://github.com/jihong88/suneditor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.47.11"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

1.*
1.10.2
1.10.4
1.11.0
1.11.4
2.*
2.0.11
2.0.13
2.0.15
2.1.1
2.10.2
2.11.1
2.12.0
2.12.3
2.12.4
2.13.1
2.14.0
2.15.2
2.15.3
2.16.1
2.16.2
2.16.3
2.17.2
2.17.3
2.18.0
2.19.1
2.2.2
2.2.4
2.2.6
2.2.7
2.20.1
2.21.0
2.21.1
2.21.2
2.22.0
2.23.3
2.23.4
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.28.0
2.28.1
2.28.2
2.28.3
2.28.4
2.29.0
2.3.0
2.30.0
2.30.1
2.30.4
2.30.5
2.30.6
2.30.7
2.31.0
2.31.1
2.31.2
2.32.0
2.32.1
2.33.0
2.33.1
2.33.3
2.34.0
2.34.1
2.34.2
2.34.3
2.35.0
2.35.1
2.36.0
2.36.1
2.36.2
2.36.4
2.36.5
2.37.0
2.37.1
2.37.2
2.37.3
2.37.4
2.38.0
2.38.1
2.38.10
2.38.2
2.38.3
2.38.4
2.38.5
2.38.6
2.38.7
2.38.8
2.39.0
2.4.1
2.4.2
2.4.3
2.40.0
2.41.0
2.41.1
2.41.2
2.41.3
2.42.0
2.43.0
2.43.10
2.43.11
2.43.14
2.43.3
2.43.4
2.43.5
2.43.6
2.43.8
2.43.9
2.44.0
2.44.1
2.44.10
2.44.12
2.44.2
2.44.3
2.44.4
2.44.5
2.44.6
2.44.7
2.44.8
2.44.9
2.45.0
2.45.1
2.46.0
2.46.1
2.46.2
2.46.3
2.47.0
2.47.1
2.47.10
2.47.5
2.47.6
2.47.7
2.47.8
2.47.9
2.5.3
2.6.3
2.7.1
2.8.0
2.8.5
2.9.2
2.9.4
2.9.5
2.9.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59167.json"