GHSA-x3wr-65j4-jv4vMediumCVSS 5.4

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

🔗 References (6)