Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.

Project Subscriptions

Vendors Products
Sakaiproject Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w2x5-gv52-9ccv Sakai Conversations has a Stored XSS Issue
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Sakaiproject
Sakaiproject sakai
Vendors & Products Sakaiproject
Sakaiproject sakai

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.
Title Sakai Conversations has a Stored XSS Issue
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:42:50.422Z

Reserved: 2026-06-11T18:24:35.095Z

Link: CVE-2026-54049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:25.587

Modified: 2026-10-01T20:17:25.587

Link: CVE-2026-54049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:45:06Z

Weaknesses