OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-61823

HIGH · CVSS 7.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects versions of the Laravel-based code16 Sharp framework prior to 9.22.5, specifically in its rich-text editor, which allows for stored cross-site scripting through the `srcdoc` attribute on iframe elements. This flaw can lead to severe impacts such as session hijacking, account takeover, and unauthorized actions when exploited by authenticated users with editing permissions. Organizations using affected versions should prioritize upgrading to 9.22.5 or implement manual sanitization of iframe content to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61823
Severity
HIGH
CVSS
7.3
EPSS
0.21%
Java

Original NVD Description

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, allowing an authenticated user with permission to edit an Editor field to store executable JavaScript that runs when another user views the content. Successful exploitation can result in session hijacking, unauthorized actions, account takeover, privilege escalation, or disclosure of administrative data. Version 9.22.5 patches the vulnerability by removing `srcdoc` from the permitted iframe attributes. As a workaround, applications that cannot upgrade should manually sanitize all Editor field content and remove every iframe `srcdoc` attribute before storing or rendering it.