PT-2026-6776 · Lute · Lute

·

CVE-2026-25647

·

Published

2026-02-06

·

Updated

2026-02-06

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lute versions prior to 1.7.7
Description Lute, a structured Markdown engine supporting Go and JavaScript, contains a Stored Cross-Site Scripting (XSS) issue in its Markdown rendering engine. An attacker can inject malicious JavaScript into Markdown text or a note. When another user clicks the rendered content, the script executes within their session.
Recommendations Update to version 1.7.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25647
GHSA-RW25-98WQ-76QV

Affected Products

Lute