PT-2026-95554 · Unknown · Md-Editor-V3

CVE-2026-84992

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions md-editor-v3 versions prior to 6.5.4
Description MdPreview fails to escape or consistently quote the fenced-code language value when inserting it into class and language HTML attributes within the useMarkdownIt() highlight callback. Because the XSSPlugin only filters existing html block and html inline tokens before rendering, it cannot inspect the HTML generated by the renderer. An attacker providing crafted Markdown can use fenced-code metadata to execute arbitrary JavaScript in the application origin when a victim renders the content, potentially leading to stored cross-site scripting if the host persists the Markdown.
Recommendations Update md-editor-v3 to version 6.5.4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84992
GHSA-3RM2-H79C-8QW6

Affected Products

Md-Editor-V3