Vulnerabilities/

Apostrophe has stored XSS via javascript: URL in Image Widget Link

Severity:
High

Description

A stored cross-site scripting vulnerability was identified in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload.

Because editors have permission to publish pages, the malicious widget can be published to the live site.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
apostrophe
Anything's wrong? Let us know Last updated on May 14, 2026