| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-32q2-hhr5-6qvv | md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commenthol
Commenthol md-fileserver |
|
| Vendors & Products |
Commenthol
Commenthol md-fileserver |
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary JavaScript execution in the context of the affected domain. This issue has been patched in version 1.10.3. | |
| Title | md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) | |
| Weaknesses | CWE-80 CWE-87 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T18:39:21.733Z
Reserved: 2026-05-14T18:06:06.811Z
Link: CVE-2026-46492
Updated: 2026-06-09T18:25:23.273Z
Status : Awaiting Analysis
Published: 2026-06-09T17:17:33.730
Modified: 2026-06-09T20:16:59.300
Link: CVE-2026-46492
No data.
OpenCVE Enrichment
Updated: 2026-06-09T20:20:12Z
Github GHSA