DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-97JJ-33GV-5XF9: GHSA-97jj-33gv-5xf9: Stored Cross-Site Scripting Bypass in league/commonmark DisallowedRawHtml Extension

GHSA-97jj-33gv-5xf9: Stored Cross-Site Scripting Bypass in league/commonmark DisallowedRawHtml Extension

Vulnerability ID: GHSA-97JJ-33GV-5XF9
CVSS Score: 6.1
Published: 2026-09-30

A security vulnerability in league/commonmark versions 1.3.0 through 2.10.1 allows remote attackers to bypass Stored Cross-Site Scripting (XSS) protections in the DisallowedRawHtml extension. Due to an validation logic flaw in the regular expression parser, specifically handling bare, unclosed HTML blocks ending at the string boundary, raw HTML tags can be passed to the rendered output. When combined with browser-side parsing heuristics, an attacker can execute arbitrary JavaScript in the context of the user session.

TL;DR

A regular expression flaw in league/commonmark allows attackers to bypass the DisallowedRawHtml filter using unclosed tags at block boundaries, resulting in Stored Cross-Site Scripting (XSS).


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-79
  • Attack Vector: Network (AV:N)
  • CVSS: 6.1 (Medium)
  • EPSS Score: N/A (No CVE assigned)
  • Exploit Status: poc
  • KEV Status: false

Affected Systems

  • Applications using league/commonmark to render Markdown to HTML with raw HTML input enabled.
  • league/commonmark: >= 1.3.0, <= 2.10.1 (Fixed in: 2.10.2)

Code Analysis

Commit: 411afcc

Fix XSS vulnerability in DisallowedRawHtmlRenderer where bare tag names terminating a block escaped sanitization

Exploit Details

  • GitHub Security Advisory: Proof of concept markdown rendering payload that bypasses DisallowedRawHtml using nested multiline sequences

Mitigation Strategies

  • Upgrade league/commonmark to version 2.10.2 or higher.
  • Set 'html_input' configuration option to 'escape' or 'strip' to block all raw HTML parsing.

Remediation Steps:

  1. Analyze composer.lock to identify the currently installed version of league/commonmark.
  2. Execute 'composer update league/commonmark' to retrieve the latest safe version (2.10.2+).
  3. If immediate patching is not possible, modify the MarkdownConverter initialization array to enforce 'html_input' => 'escape'.
  4. Verify the fix by rendering test payloads with bare HTML tags and ensuring they are escaped into safe HTML entities.

References


Read the full report for GHSA-97JJ-33GV-5XF9 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)