GHSA-97jj-33gv-5xf9: Stored Cross-Site Scripting Bypass in league/commonmark DisallowedRawHtml Extension
Vulnerability ID: GHSA-97JJ-33GV-5XF9
CVSS Score: 6.1
Published: 2026-09-30
A security vulnerability in league/commonmark versions 1.3.0 through 2.10.1 allows remote attackers to bypass Stored Cross-Site Scripting (XSS) protections in the DisallowedRawHtml extension. Due to an validation logic flaw in the regular expression parser, specifically handling bare, unclosed HTML blocks ending at the string boundary, raw HTML tags can be passed to the rendered output. When combined with browser-side parsing heuristics, an attacker can execute arbitrary JavaScript in the context of the user session.
TL;DR
A regular expression flaw in league/commonmark allows attackers to bypass the DisallowedRawHtml filter using unclosed tags at block boundaries, resulting in Stored Cross-Site Scripting (XSS).
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79
- Attack Vector: Network (AV:N)
- CVSS: 6.1 (Medium)
- EPSS Score: N/A (No CVE assigned)
- Exploit Status: poc
- KEV Status: false
Affected Systems
- Applications using league/commonmark to render Markdown to HTML with raw HTML input enabled.
-
league/commonmark: >= 1.3.0, <= 2.10.1 (Fixed in:
2.10.2)
Code Analysis
Commit: 411afcc
Fix XSS vulnerability in DisallowedRawHtmlRenderer where bare tag names terminating a block escaped sanitization
Exploit Details
- GitHub Security Advisory: Proof of concept markdown rendering payload that bypasses DisallowedRawHtml using nested multiline sequences
Mitigation Strategies
- Upgrade league/commonmark to version 2.10.2 or higher.
- Set 'html_input' configuration option to 'escape' or 'strip' to block all raw HTML parsing.
Remediation Steps:
- Analyze composer.lock to identify the currently installed version of league/commonmark.
- Execute 'composer update league/commonmark' to retrieve the latest safe version (2.10.2+).
- If immediate patching is not possible, modify the MarkdownConverter initialization array to enforce 'html_input' => 'escape'.
- Verify the fix by rendering test payloads with bare HTML tags and ensuring they are escaped into safe HTML entities.
References
- GitHub Advisory Database: GHSA-97jj-33gv-5xf9
- league/commonmark Security Advisory: XSS Bypass in DisallowedRawHtml
- Fix Commit 411afcc
Read the full report for GHSA-97JJ-33GV-5XF9 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)