PT-2026-53687 · Leandrocp · Mdex

·

CVE-2026-54889

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions leandrocp mdex versions 0.8.3 through 0.13.1
Description Improper neutralization of input during web page generation allows cross-site scripting (XSS) via unsanitized URL schemes in Quill Delta output. The function to delta/2 converts Markdown into a Quill Delta, and the function default convert node/3 copies URLs from link, wikilink, or image nodes directly into the Delta link or image attributes without normalization or applying a scheme allowlist. An attacker providing Markdown text can include a javascript: URL that is passed verbatim into the Delta attribute. When a downstream renderer converts this Delta to HTML, the attribute becomes an <a href> or <img src>, executing the script in the browser of the user. Links and wikilinks are the primary vectors as they execute on click, while images have lower impact in modern browsers.
Recommendations Update leandrocp mdex to version 0.13.2 or later. As a temporary workaround, sanitize the Quill Delta produced by to delta/2 before rendering by dropping or blanking any link or image value with a URL scheme not included in a safe allowlist (e.g., http, https, mailto, tel).

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54889
GHSA-4383-7XFP-GPPH

Affected Products

Mdex