GEM · SEPTEMBER 2026 · EARLY WARNING

decidim-elections Gem Vulnerability: Stored XSS Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
decidim-elections (gem)
Affected versions
< 0.32.0 or >= 0.22.0, <= 0.22.0 or >= 0.23.0, <= 0.23.0 or >= 0.23.1, <= 0.23.1 or >= 0.23.1.rc1, <= 0.23.1.rc1 or >= 0.23.2, <= 0.23.2 or >= 0.23.3, <= 0.23.3 or >= 0.23.4, <= 0.23.4 or >= 0.23.5, <= 0.23.5 or >= 0.23.6, <= 0.23.6 or >= 0.24.0, <= 0.24.0 or >= 0.24.0.rc1, <= 0.24.0.rc1 or >= 0.24.0.rc2, <= 0.24.0.rc2 or >= 0.24.1, <= 0.24.1 or >= 0.24.2, <= 0.24.2 or >= 0.24.3, <= 0.24.3 or >= 0.25.0, <= 0.25.0 or >= 0.25.0.rc1, <= 0.25.0.rc1 or >= 0.25.0.rc2, <= 0.25.0.rc2 or >= 0.25.0.rc3, <= 0.25.0.rc3 or >= 0.25.0.rc4, <= 0.25.0.rc4 or >= 0.25.1, <= 0.25.1 or >= 0.25.2, <= 0.25.2 or >= 0.26.0, <= 0.26.0 or >= 0.26.0.rc1, <= 0.26.0.rc1 or >= 0.26.0.rc2, <= 0.26.0.rc2 or >= 0.26.1, <= 0.26.1 or >= 0.26.10, <= 0.26.10 or >= 0.26.2, <= 0.26.2 or >= 0.26.3, <= 0.26.3 or >= 0.26.4, <= 0.26.4 or >= 0.26.5, <= 0.26.5 or >= 0.26.7, <= 0.26.7 or >= 0.26.8, <= 0.26.8 or >= 0.26.9, <= 0.26.9 or >= 0.27.0, <= 0.27.0 or >= 0.27.0.rc1, <= 0.27.0.rc1 or >= 0.27.0.rc2, <= 0.27.0.rc2 or >= 0.27.1, <= 0.27.1 or >= 0.27.10, <= 0.27.10 or >= 0.27.2, <= 0.27.2 or >= 0.27.3, <= 0.27.3 or >= 0.27.4, <= 0.27.4 or >= 0.27.5, <= 0.27.5 or >= 0.27.6, <= 0.27.6 or >= 0.27.7, <= 0.27.7 or >= 0.27.8, <= 0.27.8 or >= 0.27.9, <= 0.27.9 or >= 0.28.0, <= 0.28.0 or >= 0.28.0.rc4, <= 0.28.0.rc4 or >= 0.28.0.rc5, <= 0.28.0.rc5 or >= 0.28.1, <= 0.28.1 or >= 0.28.2, <= 0.28.2 or >= 0.28.3, <= 0.28.3 or >= 0.28.4, <= 0.28.4 or >= 0.28.5, <= 0.28.5 or >= 0.28.6, <= 0.28.6 or >= 0.31.0, <= 0.31.0 or >= 0.31.0.rc1, <= 0.31.0.rc1 or >= 0.31.0.rc2, <= 0.31.0.rc2 or >= 0.31.1, <= 0.31.1 or >= 0.31.2, <= 0.31.2 or >= 0.31.3, <= 0.31.3 or >= 0.31.4, <= 0.31.4 or >= 0.31.5, <= 0.31.5 or >= 0.31.6, <= 0.31.6 or >= 0.31.7, <= 0.31.7 or >= 0.32.0.rc1, <= 0.32.0.rc1 or >= 0.32.0.rc2, <= 0.32.0.rc2 or >= 0.32.0.rc3, <= 0.32.0.rc3
Patched version
Not yet available
GHSA-9MVP-W4RR-5C6X

An early warning has been issued for a vulnerability in the decidim-elections gem. This vulnerability allows low-privilege admins to store arbitrary HTML in election question titles, leading to stored XSS attacks.

What happened

The decidim-elections gem reportedly allows low-privilege admins to store arbitrary HTML in election question titles. This HTML is rendered unsafely in the public elections UI, enabling JavaScript execution in visitors' browsers. This vulnerability is under investigation and has not yet been exploited in the wild.

The vulnerability affects a wide range of versions of the decidim-elections gem, from versions less than 0.32.0 to various release candidates and versions up to 0.32.0.rc3. The exact version ranges and affected components should be consulted in the primary sources for detailed information.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If decidim-elections is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using the decidim-elections gem in versions less than 0.32.0 or any version from 0.22.0 to 0.32.0.rc3.

What should I do right now?

Review administrator accesses, avoid granting access to untrusted users, and monitor for patches. Apply patches as soon as they become available.

Is there an official fix available?

No official fix has been published yet. Continue to monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats