← Blog · · df00tech

Contao Comments Bundle XSS Lets Anonymous Visitors Hijack Back-End Sessions (CVE-2026-107845)

breaking ghsa composer CVE-2026-107845

What happened

A GitHub Security Advisory (GHSA-628f-v4f6-p37r) discloses a cross-site scripting vulnerability in Contao's comments bundle (contao/comments-bundle), tracked as CVE-2026-107845 with a CVSS score of 9.3 and a public proof-of-concept. Per the advisory, an unauthenticated front-end visitor can submit a comment containing an XSS payload. The injected script executes in the Contao back-end origin as soon as any back-end user opens the Comments module — no click or hover required. The advisory also notes the Contao back end sends no Content-Security-Policy header, so there is no browser-side mitigation for the inline handler.

Why it matters

This is a low-effort, unauthenticated-to-privileged escalation path. Any internet visitor can plant the payload; exposure depends only on a back-end user opening the Comments module to review it. Per the advisory, moderation does not reduce risk and arguably guarantees it, since unpublished comments are inserted into the queue regardless and a moderator must view the list to act on them. Once the payload runs in a back-end session, the advisory states it can act with that user's privileges — reading any module the user can reach, creating a new administrator, or editing a template, which on Contao is a documented route from back-end write access to code execution. Any Contao deployment using the comments bundle with front-end comment submission enabled should treat this as a path to full back-end compromise.

What defenders should do now

  • Identify all Contao installations using contao/comments-bundle and prioritize patching per the vendor advisory as soon as a fix is available.
  • Until patched, consider disabling front-end comment submission or placing comment moderation behind additional review tooling that renders content safely (not in a live back-end session context).
  • Add a Content-Security-Policy header to the Contao back end as defense-in-depth against inline script execution, independent of this specific bug.
  • Audit recent comment submissions for script-like content (event handlers, <script> tags, encoded payloads) as a hunting signal for exploitation attempts.
  • Review back-end admin accounts and templates for unexpected changes if the comments module has been in active use while unpatched.

Developing intel

This is a same-day advisory and details may evolve as the vendor and community respond. Facts above are drawn directly from the GHSA entry; no detection content or CVE details have been added beyond what is published. For the authoritative write-up, see the original GitHub Security Advisory.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.