Vulnerabilities/

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

Severity:
High

Description

  1. There is a reflected XSS vulnerability in the GET /admin/edit-codepage/:name route through the name parameter. This can be used to hijack the session of an admin if they click a specially crafted link.
  2. Additionally, there is a Command Injection vulnerability in GET /admin/backup.

Recommendation

Update the @saltcorn/server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@saltcorn/server
Anything's wrong? Let us know Last updated on January 26, 2026