CVE-2026-90835
Deferred Deferred - Pending Action

Cross-Site Scripting in itranswarp Page Content Rendering

Vulnerability report for CVE-2026-90835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: VulDB

Description

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
michaelliao itranswarp to 2.19 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in the Markdown.toHtml function of the file Markdown.java in the michaelliao itranswarp project up to version 2.19. It allows remote attackers to inject malicious scripts into web pages rendered by the component.

Detection Guidance

This vulnerability is specific to the outdated michaelliao itranswarp library up to version 2.19, where the Markdown.toHtml function in Markdown.java is vulnerable to cross-site scripting (XSS). Detection involves checking for the presence of this library and its version in your system. Since the project is no longer supported, manual inspection of dependencies is required. Look for the library in your project's dependency files (e.g., pom.xml for Maven, build.gradle for Gradle) or check installed packages. No specific commands are provided for detection as it depends on your environment and dependency management tool.

Impact Analysis

The XSS flaw may allow attackers to execute arbitrary scripts in a user's browser, potentially stealing session cookies, redirecting users to malicious sites, or performing actions on their behalf. This can lead to data theft or account compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties or reputational damage.

Mitigation Strategies

Since the affected product (michaelliao itranswarp up to 2.19) is no longer supported, the best mitigation is to discontinue use of the software. If continued use is unavoidable, implement strict input validation for Markdown content and apply network-level protections to block potential XSS attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart