PT-2026-57912 · Hedgedoc · Hedgedoc
CVE-2026-58487
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
HedgeDoc versions prior to 1.11.0
Description
Stored HTML Injection occurs due to unsafe handling of the local-part of registered email addresses. The application accepts RFC 5321 quoted-string local-parts during registration and reuses this data as the user's display name without proper escaping. This allows an attacker to inject arbitrary HTML into the collaborative editor, publish views, and slide views. Although the Content-Security-Policy prevents inline JavaScript execution, the injection can be used to modify page content and embed cross-origin iframes.
Recommendations
Update to version 1.11.0.
Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hedgedoc