Vulnerabilities/

ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context

Severity:
Medium

Description

The @apostrophecms/color-field module bypasses color validation for values prefixed with -- (intended for CSS custom properties), but performs no HTML sanitization on these values.

Recommendation

Update the apostrophe package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
apostrophe
Anything's wrong? Let us know Last updated on April 16, 2026