CVE-2026-105829
Received Received - Intake

Cross-Site Scripting in League CommonMark

Vulnerability report for CVE-2026-105829, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <script or <iframe line followed by a block supplying attributes like src or onload, executing stored scripts in viewers' browsers under default GFM settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
league commonmark From 1.3.0 (inc) to 2.10.2 (exc)
thephpleague commonmark From 1.3.0 (inc) to 2.10.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in League CommonMark versions 1.3.0 to 2.10.1. It allows attackers to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name like <script or <iframe. This lets them inject malicious attributes in subsequent Markdown content, executing stored scripts in users' browsers under default GitHub Flavored Markdown settings.

Detection Guidance

Check CommonMark library version with: composer show league/commonmark. If version is between 1.3.0 and 2.10.1, the system is vulnerable. Inspect Markdown input/output for raw HTML tags like <script or <iframe without proper escaping.

Impact Analysis

If you use a vulnerable version of League CommonMark and allow untrusted users to post Markdown, attackers could exploit this to inject malicious scripts. This could lead to stolen session cookies, account takeovers, or other malicious actions performed in users' browsers when they view the affected content.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using vulnerable software may face compliance violations if user data is compromised through this XSS flaw.

Mitigation Strategies

Upgrade League CommonMark to version 2.10.2 or later using: composer require league/commonmark:^2.10.2. If upgrading is not possible, disable the DisallowedRawHtml extension or implement input validation to block raw HTML tags in user-provided Markdown.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105829. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart