CVE-2021-26540
Estado: ModificadaMedia (5.3)—
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.75%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://advisory.checkmarx.net/advisory/CX-2021-4309
- https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#232-2021-01-26
- https://github.com/apostrophecms/sanitize-html/pull/460
- https://advisory.checkmarx.net/advisory/CX-2021-4309
- https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#232-2021-01-26
- https://github.com/apostrophecms/sanitize-html/pull/460
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-26540",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-02-08T17:15:13.737",
"references": [
{
"url": "https://advisory.checkmarx.net/advisory/CX-2021-4309",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#232-2021-01-26",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/apostrophecms/sanitize-html/pull/460",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://advisory.checkmarx.net/advisory/CX-2021-4309",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/apostrophecms/sanitize-html/blob/main/CHANGELOG.md#232-2021-01-26",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/apostrophecms/sanitize-html/pull/460",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the \"allowedIframeHostnames\" option when the \"allowIframeRelativeUrls\" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with \"/\\\\example.com\"."
},
{
"lang": "es",
"value": "Apostrophe Technologies sanitize-html versiones anteriores a 2.3.2 no comprueba correctamente los nombres de host establecidos por la opción \"allowedIframeHostnames\" cuando \"allowIframeRelativeUrls\" se establece en true, lo que permite a atacantes omitir la lista blanca de nombres de host para el elemento iframe, relacionado con un valor src que comienza con \"/\\\\example.com\""
}
],
"lastModified": "2026-06-17T03:43:27.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apostrophecms:sanitize-html:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1366C9FC-2776-4497-90A4-4B117CB54561",
"versionEndExcluding": "2.3.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}