PT-2026-95554 · Unknown · Md-Editor-V3
CVE-2026-84992
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
md-editor-v3 versions prior to 6.5.4
Description
MdPreview fails to escape or consistently quote the fenced-code language value when inserting it into class and language HTML attributes within the
useMarkdownIt() highlight callback. Because the XSSPlugin only filters existing html block and html inline tokens before rendering, it cannot inspect the HTML generated by the renderer. An attacker providing crafted Markdown can use fenced-code metadata to execute arbitrary JavaScript in the application origin when a victim renders the content, potentially leading to stored cross-site scripting if the host persists the Markdown.Recommendations
Update md-editor-v3 to version 6.5.4.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Md-Editor-V3