decidim-core
The participatory democracy framework. A generator and multiple gems made with Ruby on Rails
Activity
- Latest release
- 1mo ago
- Total releases
- 178
- Cadence
- ~2 days
- Last 12 months
- 23
Reach
- Stars
- 1.8k
Details
- License
- unknown
- First release
- Sep 16, 2016
| Version | Released | |
|---|---|---|
0.32.1
patch
|
0.32.1
patch
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
0.31.7
patch
|
0.31.7
patch
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
0.31.6
patch
|
0.31.6
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.32.0
minor
|
0.32.0
minor
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.32.0.rc3
pre
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.32.0.rc3
pre
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.32.0.rc2
pre
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.32.0.rc2
pre
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.31.5
patch
|
0.31.5
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.30.9
patch
|
0.30.9
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.32.0.rc1
pre
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.32.0.rc1
pre
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.31.4
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.31.4
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.30.8
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.30.8
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.31.3
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.31.3
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.30.7
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.30.7
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.31.2
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.31.2
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.30.6
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.30.6
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.31.1
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.31.1
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.30.5
patch
3 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |
0.30.5
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.31.0
minor
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.31.0
minor
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
0.29.7
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.7
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.30.4
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.30.4
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.31.0.rc2
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.31.0.rc2
pre
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.30.3
patch
6 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-65017
GHSA-3cx6-j9j4-54mp
Feb 03, 2026
Decidim's private data exports can lead to data leaks
High
Network
Low
Low
ImpactPrivate data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs. The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23). This issue was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:
Run the spec as many times as needed to hit a UUID that converts to The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example. The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):
Expect to see an error in the situation. Now, login as user with ID 1, go to The reason for the test case failure can be replicated in case you change the export ID to After attaching that ID, you can test if the file is available for the export:
Note that this fails with such UUID as shown in the example and could easily lead to collisions in case the UUID starts with a number. E.g. UUID Theoretical chance of collision (the reality depends on the UUID generation algorithm):
The root cause is that the class WorkaroundsFully disable the private exports feature until a patch is available. Affected versions
0.30.0
0.30.1
0.30.2
0.30.3
Fixed in
0.30.4
References
Updated Feb 08, 2026 · Source: OSV.dev |
0.30.3
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.29.6
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.6
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.31.0.rc1
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.31.0.rc1
pre
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
0.29.5
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.5
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.30.2
patch
6 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-65017
GHSA-3cx6-j9j4-54mp
Feb 03, 2026
Decidim's private data exports can lead to data leaks
High
Network
Low
Low
ImpactPrivate data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs. The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23). This issue was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:
Run the spec as many times as needed to hit a UUID that converts to The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example. The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):
Expect to see an error in the situation. Now, login as user with ID 1, go to The reason for the test case failure can be replicated in case you change the export ID to After attaching that ID, you can test if the file is available for the export:
Note that this fails with such UUID as shown in the example and could easily lead to collisions in case the UUID starts with a number. E.g. UUID Theoretical chance of collision (the reality depends on the UUID generation algorithm):
The root cause is that the class WorkaroundsFully disable the private exports feature until a patch is available. Affected versions
0.30.0
0.30.1
0.30.2
0.30.3
Fixed in
0.30.4
References
Updated Feb 08, 2026 · Source: OSV.dev |
0.30.2
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.30.1
patch
6 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-65017
GHSA-3cx6-j9j4-54mp
Feb 03, 2026
Decidim's private data exports can lead to data leaks
High
Network
Low
Low
ImpactPrivate data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs. The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23). This issue was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:
Run the spec as many times as needed to hit a UUID that converts to The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example. The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):
Expect to see an error in the situation. Now, login as user with ID 1, go to The reason for the test case failure can be replicated in case you change the export ID to After attaching that ID, you can test if the file is available for the export:
Note that this fails with such UUID as shown in the example and could easily lead to collisions in case the UUID starts with a number. E.g. UUID Theoretical chance of collision (the reality depends on the UUID generation algorithm):
The root cause is that the class WorkaroundsFully disable the private exports feature until a patch is available. Affected versions
0.30.0
0.30.1
0.30.2
0.30.3
Fixed in
0.30.4
References
Updated Feb 08, 2026 · Source: OSV.dev |
0.30.1
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.29.4
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.4
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.30.0
minor
6 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-65017
GHSA-3cx6-j9j4-54mp
Feb 03, 2026
Decidim's private data exports can lead to data leaks
High
Network
Low
Low
ImpactPrivate data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs. The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23). This issue was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:
Run the spec as many times as needed to hit a UUID that converts to The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example. The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):
Expect to see an error in the situation. Now, login as user with ID 1, go to The reason for the test case failure can be replicated in case you change the export ID to After attaching that ID, you can test if the file is available for the export:
Note that this fails with such UUID as shown in the example and could easily lead to collisions in case the UUID starts with a number. E.g. UUID Theoretical chance of collision (the reality depends on the UUID generation algorithm):
The root cause is that the class WorkaroundsFully disable the private exports feature until a patch is available. Affected versions
0.30.0
0.30.1
0.30.2
0.30.3
Fixed in
0.30.4
References
Updated Feb 08, 2026 · Source: OSV.dev |
0.30.0
minor
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.29.3
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.3
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.28.6
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.6
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.27.10
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.27.10
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.30.0.rc3
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.30.0.rc3
pre
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.30.0.rc2
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.30.0.rc2
pre
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.30.0.rc1
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.30.0.rc1
pre
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
0.28.5
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.5
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.29.2
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.2
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.29.1
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.28.4
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.4
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
0.28.3
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.3
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
0.29.0
minor
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.0
minor
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.27.9
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.27.9
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
0.27.8
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.27.8
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
0.29.0.rc4
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.0.rc4
pre
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.29.0.rc3
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.0.rc3
pre
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.28.2
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.2
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.29.0.rc1
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.0.rc1
pre
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.27.7
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.27.7
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
0.29.0.rc2
pre
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.29.0.rc2
pre
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.28.1
patch
5 CVEs
CVE-2026-45573
GHSA-2g9c-vf8h-prxx
Jul 13, 2026
Decidim: Push subscriptions can be abused for server-side requests
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
DescriptionThe push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-request sink when VAPID delivery is enabled. The practical result is an authenticated, stored, mostly blind SSRF primitive to arbitrary HTTPS endpoints reachable from the app server. Technical descriptionWhen VAPID delivery is enabled, the notification subscription flow stores the client-supplied push endpoint without checking that it belongs to an approved push service. The send path later passes that stored URL to
One spec asserts that the endpoint is persisted exactly as supplied:
Another spec asserts that
Impact
PatchesSee https://github.com/decidim/decidim/pull/16714. WorkaroundsDisable the push notifications feature by removing the VAPID keys in the server. ResourceSSRF CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45572
GHSA-533c-2vh9-4r86
Jul 13, 2026
Decidim: HTML content blocks allow stored script execution
4.8
/ 10
Medium
Network
Low
High
Required
Changed
Low
Low
None
DescriptionA privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an Technical descriptionThis issue lets any admin who can edit an affected landing page store arbitrary HTML and JavaScript in an Impact
PatchesSee https://github.com/decidim/decidim/pull/16451 WorkaroundsDo not give admin permissions to non-trustful users. ReferenceStored XSS CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45377
GHSA-767h-63j4-5226
Jul 13, 2026
Decidim: Private exports can be downloaded through reusable links
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
DescriptionThe normal Technical descriptionThis private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI.
Step 2. Download through the authenticated wrapper route.
Step 3. Capture the final bearer URL in the redirect chain.
Step 4. Replay the final file URL without authentication.
ImpactPersonal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable Private Downloads URLs ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
0.0.1.alpha9
0.0.2
0.0.3
+ 160 more Show less
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40869
GHSA-w5xj-99cg-rccm
Apr 14, 2026
Decidim amendments can be accepted or rejected by anyone
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. The only check done when accepting or rejecting amendments is whether the amendment reactions are enabled for the component: https://github.com/decidim/decidim/blob/9d6c3d2efe5a83bb02e095824ff5998d96a75eb7/decidim-core/app/permissions/decidim/permissions.rb#L107 The permission checks have been changed at 1b99136 which was introduced in released version 0.19.0. I have not investigated whether prior versions are also affected. PatchesNot available WorkaroundsDisable amendment reactions for the amendable component (e.g. proposals). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
+ 72 more Show less
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
Fixed in
0.30.5
0.31.1
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-23891
GHSA-fc46-r95f-hq7g
Apr 13, 2026
Decidim has a cross-site scripting (XSS) in user name
Critical
Network
Low
Low
ImpactA stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries. PatchesN/A WorkaroundsNot available ReferencesOWASP ASVS v4.0.3-5.1.3 CreditsThis issue was discovered in a security audit organized by octree and made by Secu Labs against Decidim financed by the city of Lausanne (Switzerland). Affected versions
0.31.0
0.31.0.rc1
0.31.0.rc2
0.0.1
0.0.1.alpha1
0.0.1.alpha2
0.0.1.alpha3
0.0.1.alpha4
0.0.1.alpha5
0.0.1.alpha6
0.0.1.alpha7
0.0.1.alpha8
+ 149 more Show less
0.0.1.alpha9
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
0.0.8.1
0.1.0
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2.0
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.3.0
0.3.1
0.3.2
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.30.5
0.31.1
References
Updated May 13, 2026 · Source: OSV.dev |
0.28.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|