CVE-2026-54049
Received Received - Intake

Stored XSS in Sakai Conversations Tool

Vulnerability report for CVE-2026-54049, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
sakai_project sakai From 23.0 (inc) to 23.5 (exc)
sakai_project sakai From 25.0 (inc) to 25.3 (exc)
sakai_project sakai 23.5
sakai_project sakai 25.3
sakai_project sakai 26.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Sakai Collaboration and Learning Environment. It occurs because the Conversations tool stores user messages without sanitizing HTML or JavaScript code. When other users view these messages, the frontend renders them unsafely, allowing injected scripts to execute in their browsers.

Detection Guidance

Check Sakai versions for affected releases (23.0 to 23.4, 25.0 to 25.2). Inspect Conversations tool messages for unsanitized HTML/JavaScript in database or frontend rendering. Look for LitElement unsafeHTML() usage in frontend code.

Impact Analysis

An attacker with site access can inject malicious scripts into conversations. These scripts may steal sensitive data like gradebook information, perform actions on behalf of victims, or compromise all users viewing the affected content. The attack requires only basic user privileges.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Organizations using vulnerable Sakai versions may face compliance violations if exploited.

Mitigation Strategies

Upgrade Sakai to patched versions (23.5, 25.3, or 26.0). Apply input sanitization for Conversations tool content using FormattedText service with high security level. Review and sanitize existing stored messages in the database.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54049. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart