Cross-Site Scripting Vulnerability in Logseq Developed by Logseq
CVE-2025-56683
9.6CRITICAL
What is CVE-2025-56683?
A cross-site scripting (XSS) vulnerability exists within the Logseq application as of version 0.10.9, specifically located in the /app/marketplace.html component. This vulnerability allows attackers to execute arbitrary code by injecting malicious JavaScript through carefully crafted README.md files. Exploiting this flaw could lead to unauthorized actions being performed in the context of a user's session, compromising user data and security.
