Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.sakaiproject.rubrics/rubrics-impl
  4. ›
  5. CVE-2026-54049

CVE-2026-54049: Sakai Conversations has a Stored XSS Issue

August 24, 2026

The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement’s unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post.

References

  • github.com/advisories/GHSA-w2x5-gv52-9ccv
  • github.com/sakaiproject/sakai/commit/2696b4b48cbef2e81512f52f84f7477adff78b27
  • github.com/sakaiproject/sakai/releases/tag/23.5
  • github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv
  • nvd.nist.gov/vuln/detail/CVE-2026-54049

Code Behaviors & Features

Detect and mitigate CVE-2026-54049 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 23.0.0 up to 23.3.0

Solution

Unfortunately, there is no solution available yet.

Impact 8.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

maven/org.sakaiproject.rubrics/rubrics-impl/CVE-2026-54049.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 25 Aug 2026 00:18:02 +0000.