CVE-2026-105829

Source
https://cve.org/CVERecord?id=CVE-2026-105829
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105829.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105829
Aliases
Downstream
Published
2026-10-08T14:10:30Z
Modified
2026-10-10T02:30:35Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass
Details

League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <script or <iframe line followed by a block supplying attributes like src or onload, executing stored scripts in viewers' browsers under default GFM settings.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-80"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105829.json"
}
References

Affected packages

Git / github.com/thephpleague/commonmark

Affected ranges

Type
GIT
Repo
https://github.com/thephpleague/commonmark
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "fixed": "2.10.2"
        }
    ],
    "source": "DESCRIPTION"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105829.json"