Cross-Site Scripting Vulnerability in league/commonmark Affected by thephpleague
CVE-2026-86431
6.9MEDIUM
What is CVE-2026-86431?
The league/commonmark component versions 2.7.0 to 2.9.0 are susceptible to a cross-site scripting vulnerability within the AttributesExtension. By using a U+000C form feed byte to prefix attribute names, attackers can bypass the intended attribute filtering mechanisms. This allows malicious scripts to be injected into the rendered HTML, executing JavaScript when a user views the output. This issue requires the processing of untrusted Markdown while having the AttributesExtension enabled. The vulnerability is addressed in version 2.9.1.
Affected Version(s)
commonmark 2.7.0 < 2.9.1
commonmark 2.9.1
