StackRadar

CVE-2026-84371

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
sanitize-htmlnpm1.14.1, 1.18.5, 1.19.1, 1.27.5+11 more2.17.753
OSV records
GHSA-g8qq-57p8-ggw5

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
sanitize-html@2.17.0
2.17.7

Open the chart page →

4,684
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
sanitize-html@2.12.1
2.17.7

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
sanitize-html@2.12.1
2.17.7

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
sanitize-html@2.8.1
2.17.7

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
sanitize-html@2.12.1
2.17.7

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
sanitize-html@2.12.1
2.17.7

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
sanitize-html@2.12.1
2.17.7

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
sanitize-html@2.12.1
2.17.7

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
sanitize-html@2.12.1
2.17.7

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
sanitize-html@2.12.1
2.17.7

Open the chart page →

11,100
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
sanitize-html@2.13.0
2.17.7

Open the chart page →

676
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84371.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
sanitize-html@2.7.0
2.17.7

Open the chart page →

4,017

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sanitize-html@1.27.5
2.17.7
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
sanitize-html@2.11.0
2.17.7
3
governify/assets-manager:v1.4.12987672448c7
sanitize-html@1.27.5
2.17.7
2
library/ghost:6.63.0e05bc1169fb2
sanitize-html@2.17.5
2.17.7
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sanitize-html@1.27.5
2.17.7
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sanitize-html@1.27.5
2.17.7
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sanitize-html@1.27.5
2.17.7
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sanitize-html@1.27.5
2.17.7
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
sanitize-html@1.27.5
2.17.7
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
sanitize-html@2.12.1
2.17.7
2
n8nio/n8n:2.36.714c4285bc303
sanitize-html@2.17.5
2.17.7
2
n8nio/n8n:2.38.45d9f0cc5672b
sanitize-html@2.17.5
2.17.7
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
sanitize-html@1.19.1
2.17.7
1
chocobozzz/peertube:v8.1.5052712130691
sanitize-html@2.17.1
2.17.7
1
daskdev/dask-notebook:1.1.0052630f5ca04
sanitize-html@1.18.5
2.17.7
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
sanitize-html@2.13.0
2.17.7
1
directus/directus:12.0.29c8470ea465c
sanitize-html@2.17.0
2.17.7
1
directus/directus:11.1.0e3c8bb975350
sanitize-html@2.13.0
2.17.7
1
diygod/rsshub:2025-11-097a6312cac0d5
sanitize-html@2.17.0
2.17.7
1
library/ghost:6.37.01ef2e532ca4d
sanitize-html@2.17.0
2.17.7
1
library/ghost:6.25.12654b1e90413
sanitize-html@2.17.0
2.17.7
1
library/ghost:6.41.129773d6be407
sanitize-html@2.17.4
2.17.7
1
library/ghost:4.37.0767230c0f263
sanitize-html@2.7.0
2.17.7
1
library/ghost:6.39.0-alpine77196da4b0df
sanitize-html@2.17.0
2.17.7
1
library/ghost:5.79.083f7bf209844
sanitize-html@2.11.0
2.17.7
1
library/ghost:6.62.0a7a268bbfb7f
sanitize-html@2.17.5
2.17.7
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
sanitize-html@2.17.0
2.17.7
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
sanitize-html@1.14.1
2.17.7
1
misskey/misskey:12.110.1e08b7c478093
sanitize-html@2.7.0
2.17.7
1
n8nio/n8n:2.25.7761374d4eb84
sanitize-html@2.12.1
2.17.7
1
n8nio/n8n:1.86.08b39ed5a2de9
sanitize-html@2.12.1
2.17.7
1
n8nio/n8n:0.212.0a9195bc499a3
sanitize-html@2.7.0
2.17.7
1
n8nio/n8n:2.36.8cfe2704ff858
sanitize-html@2.17.5
2.17.7
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
sanitize-html@2.17.6
2.17.7
1
polonel/trudesk:1.2.60cf6513f6fe3
sanitize-html@2.7.0
2.17.7
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
sanitize-html@2.8.1
2.17.7
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.26.379f14a2bf931
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
sanitize-html@2.12.1
2.17.7
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
sanitize-html@2.12.1
2.17.7
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
sanitize-html@2.7.0
2.17.7
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
sanitize-html@2.11.0
2.17.7
1
ghcr.io/data-fair/portals:18b621866ceb2
sanitize-html@1.27.5
2.17.7
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
sanitize-html@2.17.0
2.17.7
1
ghcr.io/quenchworks/images/xyopsdd7d8bf3b654
sanitize-html@2.17.5
2.17.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.