GHSA-vj3q-vp3g-j9c8HighCVSS 8.7

code16/sharp has a stored XSS via data-html-content Sanitizer Bypass

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The vulnerability allows an attacker to bypass the HTML sanitizer by using the data-html-content attribute in the content of a SharpEditorFormField.

Patches

The field must now explicitly configure SharpFormEditorField::RAW_HTML in the toolbar to keep this behavior. When using the RAW_HTML button, the application using code16/sharp must sanitize manually the content coming from the field. Vulnerability has been patched in version 9.22.5.

Workarounds

Sanitize every contents of editors manually (e.g. using Symfony/HtmlSanitizer)

🎯 Affected products1

  • composer/code16/sharp:< 9.22.5

🔗 References (4)