Contao Comments Bundle XSS Lets Anonymous Visitors Hijack Back-End Sessions (CVE-2026-107845)
What happened
A GitHub Security Advisory (GHSA-628f-v4f6-p37r) discloses a cross-site scripting vulnerability in Contao's comments bundle (contao/comments-bundle), tracked as CVE-2026-107845 with a CVSS score of 9.3 and a public proof-of-concept. Per the advisory, an unauthenticated front-end visitor can submit a comment containing an XSS payload. The injected script executes in the Contao back-end origin as soon as any back-end user opens the Comments module — no click or hover required. The advisory also notes the Contao back end sends no Content-Security-Policy header, so there is no browser-side mitigation for the inline handler.
Why it matters
This is a low-effort, unauthenticated-to-privileged escalation path. Any internet visitor can plant the payload; exposure depends only on a back-end user opening the Comments module to review it. Per the advisory, moderation does not reduce risk and arguably guarantees it, since unpublished comments are inserted into the queue regardless and a moderator must view the list to act on them. Once the payload runs in a back-end session, the advisory states it can act with that user's privileges — reading any module the user can reach, creating a new administrator, or editing a template, which on Contao is a documented route from back-end write access to code execution. Any Contao deployment using the comments bundle with front-end comment submission enabled should treat this as a path to full back-end compromise.
What defenders should do now
- Identify all Contao installations using
contao/comments-bundleand prioritize patching per the vendor advisory as soon as a fix is available. - Until patched, consider disabling front-end comment submission or placing comment moderation behind additional review tooling that renders content safely (not in a live back-end session context).
- Add a
Content-Security-Policyheader to the Contao back end as defense-in-depth against inline script execution, independent of this specific bug. - Audit recent comment submissions for script-like content (event handlers,
<script>tags, encoded payloads) as a hunting signal for exploitation attempts. - Review back-end admin accounts and templates for unexpected changes if the comments module has been in active use while unpatched.
Developing intel
This is a same-day advisory and details may evolve as the vendor and community respond. Facts above are drawn directly from the GHSA entry; no detection content or CVE details have been added beyond what is published. For the authoritative write-up, see the original GitHub Security Advisory.