CVE-2026-23891
Impact
A stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries.
Patches
N/A
Workarounds
Not available
References
OWASP ASVS v4.0.3-5.1.3
Credits
This issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/decidim/decidim/security/advisories/GHSA-fc46-r95f-hq7g, https://github.com/decidim/decidim, https://github.com/decidim/decidim/releases/tag/v0.30.5, https://github.com/decidim/decidim/releases/tag/v0.31.1
