Sceawere

Vulnerability Detail

CVE-2026-54049UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sakai Conversations Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
1d ago
Vendor
sakaiproject
Product
sakai
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-01T20:17:25.587Z",
  "pubdate": "2026-10-01T20:17:25.587Z",
  "executiveSummary": "Sakai, a Collaboration and Learning Environment (CLE), is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability within its Conversations tool.\nThe vulnerability originates from a failure to perform adequate HTML sanitization on user-supplied input for topic and post messages.\nThe frontend renders this unsanitized content using the LitElement unsafeHTML() directive, which bypasses built-in security protections.\nAn authenticated attacker with access to a site containing the Conversations tool can inject arbitrary HTML and JavaScript payloads.\nThese payloads execute automatically within the browser sessions of any user who views the compromised topic or post.\nSuccessful exploitation allows an attacker to perform actions on behalf of the victim, steal session cookies, capture sensitive data, or redirect users to malicious external domains.\nThe vulnerability affects Sakai versions 23.0 through 23.4 and 25.0 through 25.2.\nThe risk is significant as it facilitates unauthorized interaction and potential account compromise within a collaborative educational environment.",
  "technicalDetails": "The vulnerability is a classic Stored XSS flaw stemming from the improper handling of user-generated content within the Sakai Conversations tool. The root cause is the storage of message payloads without server-side sanitization, coupled with the application's client-side rendering logic.\nThe application utilizes the LitElement framework's unsafeHTML() directive to render dynamic content. The unsafeHTML() directive is specifically designed to render strings as HTML, explicitly bypassing the framework's default protection against XSS. By design, it assumes that the developer has sanitized the input before passing it to the directive; however, in the Conversations tool, this prerequisite is not met.\nAttack flow begins with an authenticated user crafting a malicious payload containing JavaScript, such as an event handler (e.g., onerror, onload) or a script tag, embedded within a Sakai Conversations post or topic message. Upon submission, the Sakai backend accepts the input and persists it directly into the database without removing or escaping potentially dangerous HTML tags or attributes.\nWhen another user navigates to the Conversations tool to view the affected topic or post, the frontend retrieves the malicious payload from the database. The client-side application then passes this raw, unsanitized string into the unsafeHTML() directive. The browser parses the injected HTML and executes the attacker's JavaScript code within the context of the victim's current session.\nBecause the payload is stored persistently in the database, the script executes every time the content is rendered for any user viewing the page. This creates a persistent threat surface. The impact of successful exploitation is high, as the script operates within the origin of the Sakai instance, granting the attacker access to the victim’s session-based tokens, local storage, and the ability to perform authorized actions on behalf of the victim (e.g., changing account settings or accessing private course data).\nAffected versions are explicitly identified as Sakai 23.0 through before 23.5, and 25.0 through before 25.3. The lack of input validation and the reliance on insecure rendering directives represent a fundamental architectural weakness in the handling of user-provided content within the Conversations component."
}
CVE-2026-54049: Sakai Conversations Stored XSS (HIGH Severity, CVSS: 8.7) | Sceawere