CVE-2026-26028
CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of <iframe>, <video>, and <audio> elements, leaving all other attributes unchecked. As a result, an attacker can inject arbitrary HTML through srcdoc, completely defeating CryptPad's intended bounce sandboxing and enabling link injection or other interactive content within user-controlled documents.
Leer descripción completaMostrar menos
The root cause lies in how the sanitizer classifies and enforces tag restrictions: although it defines both forbidden and restricted tag lists, <iframe> is treated as "restricted" rather than "forbidden." Enforcement then inspects only the src attribute, so pairing a benign blob: src with a malicious srcdoc results in unrestricted rendering. This issue has been fixed in version 2026.2.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-79, CWE-116
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-26028",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-26028",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-20T19:31:12.220425Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "cryptpad",
"product": "cryptpad",
"versions": [
{
"status": "affected",
"version": "< 2026.2.0"
}
]
}
]
}
],
"published": "2026-05-20T20:16:36.760",
"references": [
{
"url": "https://github.com/cryptpad/cryptpad/releases/tag/2026.2.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/cryptpad/cryptpad/security/advisories/GHSA-g2g4-47gv-p72v",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
},
{
"lang": "en",
"value": "CWE-116"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of <iframe>, <video>, and <audio> elements, leaving all other attributes unchecked. As a result, an attacker can inject arbitrary HTML through srcdoc, completely defeating CryptPad's intended bounce sandboxing and enabling link injection or other interactive content within user-controlled documents. The root cause lies in how the sanitizer classifies and enforces tag restrictions: although it defines both forbidden and restricted tag lists, <iframe> is treated as \"restricted\" rather than \"forbidden.\" Enforcement then inspects only the src attribute, so pairing a benign blob: src with a malicious srcdoc results in unrestricted rendering. This issue has been fixed in version 2026.2.0."
},
{
"lang": "es",
"value": "CryptPad es una suite ofimática colaborativa cifrada de extremo a extremo. En versiones anteriores a la 2026.2.0, el saneador de HTML en Diffmarked.js puede ser eludido debido a un filtrado incompleto de atributos en etiquetas restringidas. El saneador valida solo el atributo src de los elementos <iframe>, <video> y <audio>, dejando todos los demás atributos sin verificar. Como resultado, un atacante puede inyectar HTML arbitrario a través de srcdoc, anulando por completo el sandboxing de rebote previsto de CryptPad y permitiendo la inyección de enlaces u otro contenido interactivo dentro de documentos controlados por el usuario. La causa raíz reside en cómo el saneador clasifica y aplica las restricciones de etiquetas: aunque define listas de etiquetas prohibidas y restringidas, <iframe> es tratado como 'restringido' en lugar de 'prohibido'. La aplicación luego inspecciona solo el atributo src, por lo que emparejar un src benigno de tipo blob: con un srcdoc malicioso resulta en una renderización sin restricciones. Este problema ha sido solucionado en la versión 2026.2.0."
}
],
"lastModified": "2026-07-23T12:10:00.110",
"sourceIdentifier": "security-advisories@github.com"
}