# Security Release for issue #14290

**URL:** https://discuss.tryton.org/t/security-release-for-issue-14290/8895
**Category:** News
**Tags:** security
**Created:** [October 21, 2025, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14290/8895 "2025-10-21T06:00:02Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [October 21, 2025, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14290/8895/1 "2025-10-21T06:00:02Z")

</div>

[Brandon Da Costa](https://foss.heptapod.net/f10ww) and [Mahdi Afshar](https://foss.heptapod.net/Mahdi36) have found that [sao](https://www.npmjs.com/package/tryton-sao) [executes JavaScript included in HTML documents](https://bugs.tryton.org/14290) (such as attachments). These documents may be uploaded by any authenticated user. The JavaScript is executed in the same context as sao which gives access to sensitive data such as the session.

## Impact

[CVSS v3.0 Base Score: 7.3](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:H/RL:O/RC:C/CR:H/IR:H/MAV:N/MAC:L/MPR:L/MUI:R/MS:U/MC:H/MI:H/MA:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: High
- Integrity: High
- Availability: None

If the `inbound_email` and `document_incoming` modules are activated, the impact increases as anybody can send emails with attachments: [CVSS v3.0 Base Score: 8.1](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:H/RL:O/RC:C/CR:H/IR:H/MAV:N/MAC:L/MPR:L/MUI:R/MS:U/MC:H/MI:H/MA:N)

## Workaround

There is no general workaround.  
For inbound email blocking emails with HTML attachments will block this attack vector.

## Resolution

All affected users should upgrade `sao` to the latest version.

Affected versions per series:

- `sao`:
  - 7.6: \<= 7.6.8
  - 7.4: \<= 7.4.18
  - 7.0: \<= 7.0.37
  - 6.0: \<= 6.0.66

Non affected versions per series:

- `sao`:
  - 7.6: \>= 7.6.9
  - 7.4: \>= 7.4.19
  - 7.0: \>= 7.0.38
  - 6.0: \>= 6.0.67

## Reference

- [Stored XSS Vulnerability Found - Attachments Preview (#14290) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/14290)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [November 20, 2025, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14290/8895/2 "2025-11-20T06:00:41Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
