DOM Cross-Site Scripting Vulnerability in Milkdown by Milkdown
CVE-2026-57531

5.1MEDIUM

Key Information:

Vendor

Milkdown

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-57531?

Milkdown versions before 7.21.3 are susceptible to a DOM-based cross-site scripting vulnerability within the @milkdown/plugin-emoji package. This flaw enables unauthenticated attackers to execute arbitrary JavaScript code by manipulating the content that victims paste into applications utilizing the plugin. Specifically, the vulnerability arises due to the parseDOM.getAttrs handler, which improperly handles raw innerHTML of pasted emoji span elements without adequate sanitization. As a result, malicious scripts can be directly injected into the live DOM by exploiting the toMarkdown runner, effectively bypassing the protection provided by DOMPurify, and leading to payload execution during markdown serialization. Users of Milkdown should update to the latest version to mitigate exposure to this vulnerability.

Affected Version(s)

milkdown 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
.