HIGH 8.7 GitHub
CVE-2026-54049
Sakai Conversations has a Stored XSS Issue
### Summary
The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post.
### Description
The Conversations REST API endpoint `POST /api/sites/{
Affected Products
- maven/org.sakaiproject.conversations:sakai-conversations-impl >= 23.0, <= 23.3
- maven/org.sakaiproject.kernel:sakai-kernel-impl >= 23.0, <= 23.3
- maven/org.sakaiproject.rubrics:rubrics-impl >= 23.0, <= 23.3
References
- https://github.com/advisories/GHSA-w2x5-gv52-9ccv
- https://github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv
- https://github.com/sakaiproject/sakai/commit/2696b4b48cbef2e81512f52f84f7477adff78b27
- https://github.com/sakaiproject/sakai/releases/tag/23.5
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-24 via GitHub. Affected: maven/org.sakaiproject.conversations:sakai-conversations-impl >= 23.0, <= 23.3, maven/org.sakaiproject.kernel:sakai-kernel-impl >= 23.0, <= 23.3, maven/org.sakaiproject.rubrics:rubrics-impl >= 23.0, <= 23.3.
vulnfeed aggregates 11313 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.