GHSA-6hqx-4r22-f9m2Medium

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows...

Published
August 13, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (1)

📋 Description

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes

🔗 References (5)