Impact
League CommonMark versions 1.3.0 through 2.10.1 allow an attacker to embed malicious markup in user‑submitted Markdown by terminating raw HTML with an unmatched disallowed tag name. The DisallowedRawHtml extension normally blocks raw tags such as <script> or <iframe>, but the bypass permits the attacker to place a lone <script or <iframe tag followed by a second line that supplies attributes like src or onload. When the Markdown is rendered under default GitHub‑Flavored Markdown settings, the browser executes the injected code and stores it for future viewers, resulting in stored cross‑site scripting. The impact is the compromise of client‑side confidentiality and integrity, permitting attackers to run arbitrary JavaScript in the context of authenticated users.
Affected Systems
The vulnerability is limited to packages released by thephpleague named CommonMark, specifically data models from version 1.3.0 up to and including 2.10.1. The affected distribution is public and used by a wide range of PHP projects that process Markdown content.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so no known high‑profile exploits have been reported at this time. The attack can be carried out as anyone who can insert Markdown into the application, such as through a feedback form or comment section, and the payload persists in the rendered content, affecting all users who view the page. Proper configuration of the DisallowedRawHtml extension or newer versions mitigates the attack.
OpenCVE Enrichment