Description
A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (remote)
Action: Deploy Mitigation
AI Analysis

Impact

The flaw resides in the Markdown.toHtml function of the Page Content Rendering component in itranswarp. By supplying crafted Markdown input, an attacker can cause the function to produce output that includes arbitrary HTML and JavaScript, which The vulnerability is a cross‑site scripting flaw that can be triggered remotely, and an exploit has already been published.

Affected Systems

This vulnerability affects only the itranswarp product released by michaelliao, specifically versions up to and including 2.19. Versions newer than 2.19 are not known to be vulnerable, and the maintainers have not yet released a patch for the affected releases.

Risk and Exploitability

The CVSS base score of 5.1 suggests a moderate impact. The EPSS score is below 1 %, indicating a very low expected exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. However, because the flaw is exploitable remotely and an exploit is publicly available, systems that remain on the vulnerable versions face a meaningful risk of cross‑site scripting attacks.

Generated by OpenCVE AI on September 17, 2026 at 18:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or remove the rendering of user‑supplied Markdown so that the vulnerable Markdown.toHtml function is never invoked.
  • If disabling Markdown is impractical, sanitize the generated HTML by stripping or escaping all tags that can execute scripts, thereby mitigating the CWE‑79 and CWE‑94 weaknesses.
  • Deploy a strict Content Security Policy header that disallows inline scripts and restricts script sources to trusted domains.

Generated by OpenCVE AI on September 17, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.
Title michaelliao itranswarp Page Content Rendering Markdown.java Markdown.toHtml cross site scripting
First Time appeared Michaelliao
Michaelliao itranswarp
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:michaelliao:itranswarp:*:*:*:*:*:*:*:*
Vendors & Products Michaelliao
Michaelliao itranswarp
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Michaelliao Itranswarp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:50:46.327Z

Reserved: 2026-09-13T19:23:30.342Z

Link: CVE-2026-90835

cve-icon Vulnrichment

Updated: 2026-09-15T13:50:38.653Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T23:18:59.973

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')