CVE-2026-24127

Source
https://cve.org/CVERecord?id=CVE-2026-24127
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24127.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24127
Aliases
  • GHSA-65x4-pjhj-r8wr
Published
2026-01-23T23:01:15.832Z
Modified
2026-03-01T02:56:47.412453Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Typemill has Reflected XSS via login error view template
Details

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template login.twig of versions 2.19.1 and below. The username value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-116",
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24127.json"
}
References

Affected packages

Git / github.com/typemill/typemill

Affected ranges

Type
GIT
Repo
https://github.com/typemill/typemill
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.01
1.1.1
1.1.1.0
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
2.*
2.15.0
2.16.0
2.16.1
2.16.2
2.6.0
Other
latest
v2.*
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.18.4
v2.19.0
v2.19.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24127.json"