A stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries.
N/A
Not available
OWASP ASVS v4.0.3-5.1.3
This issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland).
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-13T16:35:13Z",
"nvd_published_at": "2026-04-13T17:16:28Z",
"severity": "CRITICAL"
}