PT-2026-57912 · Hedgedoc · Hedgedoc

CVE-2026-58487

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions HedgeDoc versions prior to 1.11.0
Description Stored HTML Injection occurs due to unsafe handling of the local-part of registered email addresses. The application accepts RFC 5321 quoted-string local-parts during registration and reuses this data as the user's display name without proper escaping. This allows an attacker to inject arbitrary HTML into the collaborative editor, publish views, and slide views. Although the Content-Security-Policy prevents inline JavaScript execution, the injection can be used to modify page content and embed cross-origin iframes.
Recommendations Update to version 1.11.0.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58487
GHSA-6C2W-8W96-3PCV

Affected Products

Hedgedoc