Stored HTML Attribute Injection Vulnerability in Typemill Content Management System
CVE-2026-53468
4.6MEDIUM
What is CVE-2026-53468?
Typemill, a flat-file, Markdown-based content management system for documentation websites, is vulnerable to stored HTML attribute injection in the page metadata fields ('og:title' and 'og:description'). An authenticated user with permission to modify page metadata can exploit this flaw to inject arbitrary HTML attributes into generated tags. This vulnerability stems from a lack of proper output encoding, allowing for potential stored cross-site scripting (XSS) under certain browser or DOM interaction conditions. Users are advised to upgrade to version 2.23.0 to mitigate this risk.
Affected Version(s)
typemill < 2.23.0
