Description
League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <script or <iframe line followed by a block supplying attributes like src or onload, executing stored scripts in viewers' browsers under default GFM settings.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Stored cross‑site scripting via DisallowedRawHtml bypass
Action: Apply patch
AI Analysis

Impact

League CommonMark versions 1.3.0 through 2.10.1 allow an attacker to embed malicious markup in user‑submitted Markdown by terminating raw HTML with an unmatched disallowed tag name. The DisallowedRawHtml extension normally blocks raw tags such as <script> or <iframe>, but the bypass permits the attacker to place a lone <script or <iframe tag followed by a second line that supplies attributes like src or onload. When the Markdown is rendered under default GitHub‑Flavored Markdown settings, the browser executes the injected code and stores it for future viewers, resulting in stored cross‑site scripting. The impact is the compromise of client‑side confidentiality and integrity, permitting attackers to run arbitrary JavaScript in the context of authenticated users.

Affected Systems

The vulnerability is limited to packages released by thephpleague named CommonMark, specifically data models from version 1.3.0 up to and including 2.10.1. The affected distribution is public and used by a wide range of PHP projects that process Markdown content.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so no known high‑profile exploits have been reported at this time. The attack can be carried out as anyone who can insert Markdown into the application, such as through a feedback form or comment section, and the payload persists in the rendered content, affecting all users who view the page. Proper configuration of the DisallowedRawHtml extension or newer versions mitigates the attack.

Generated by OpenCVE AI on October 8, 2026 at 15:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CommonMark library to version 2.10.2 or later.
  • Verify that the DisallowedRawHtml extension is enabled in the Markdown parser configuration and that it blocks all disallowed tags.
  • If an upgrade is not immediately possible, strip or sanitize raw HTML from user input before rendering or switch the parser to a stricter mode that disables raw tags completely.

Generated by OpenCVE AI on October 8, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <script or <iframe line followed by a block supplying attributes like src or onload, executing stored scripts in viewers' browsers under default GFM settings.
Title League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass
First Time appeared Thephpleague
Thephpleague commonmark
Weaknesses CWE-80
CPEs cpe:2.3:a:thephpleague:commonmark:-:*:*:*:*:*:*:*
Vendors & Products Thephpleague
Thephpleague commonmark
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Thephpleague Commonmark
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T15:22:12.780Z

Reserved: 2026-10-05T21:59:09.591Z

Link: CVE-2026-105829

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:35.167

Modified: 2026-10-08T16:17:01.517

Link: CVE-2026-105829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:17Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)