Decidim has a cross-site scripting (XSS) in user name
Package
Affected versions
>= 0.31.0.rc1, < 0.31.0
< 0.30.5
Patched versions
0.31.1
0.30.5
Description
Published to the GitHub Advisory Database
Apr 13, 2026
Reviewed
Apr 13, 2026
Published by the National Vulnerability Database
Apr 13, 2026
Last updated
May 13, 2026
Impact
A stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries.
Patches
N/A
Workarounds
Not available
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland).
References