GHSA-rwcv-whm8-fmxmMediumCVSS 6.1

GeoNode: Stored XSS to full account takeover

Published
July 13, 2026
Last Modified
July 13, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a request to change another user's email address to perform a full account takeover. Due to the script element not impacting the CORS policy, requests will succeed.

🎯 Affected products1

  • pip/geonode:>= 3.2.1, < 4.2.3

🔗 References (5)