PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74234 Legora CVE debrief

The Legora application before version 2026-08-14 contains a cross-site scripting vulnerability, allowing attackers to execute arbitrary JavaScript in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. Users of Legora before version 2026-08-14, administrators of systems with Legora installed, security teams monitoring for cross-site scripting vulnerabilities, and operators of Word and Outlook add-in surfaces where bearer session tokens are persisted in localStorage should be aware of this vulnerability and take necessary precautions to protect their systems and data. The CVE record was published on 2026-08-17T20:16:46.813Z and has not been modified since then. The NVD entry is currently Received.

Vendor
Legora
Product
Unknown
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-08-21
Advisory published
2026-08-17
Advisory updated
2026-08-21

Who should care

Users of Legora before version 2026-08-14, administrators of systems with Legora installed, security teams monitoring for cross-site scripting vulnerabilities, and operators of Word and Outlook add-in surfaces where bearer session tokens are persisted in localStorage should be aware of this vulnerability and take necessary precautions to protect their systems and data. They should review and update Legora installations to version 2026-08-14 or later, implement additional input validation and sanitization for Mermaid diagram content, and monitor user browser interactions for suspicious activity. Security teams should prioritize this vulnerability for review and remediation due to its potential impact on user browser context and elevated impact on Word and Outlook add-in surfaces. Compensating controls should be considered for exposed systems while remediation is scheduled and verified. Exceptions, retested remediated assets, and evidence documentation are crucial for closing the item effectively. Asset inventory and source tracking can help in managing the remediation process effectively. Rollback change windows may be necessary for systems that cannot be updated immediately. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. This requires coordination with affected product deployments in managed environments, assigning owners for follow-up, and tracking the remediation process. Vulnerability management teams should ensure that all necessary steps are taken to mitigate this vulnerability across the organization. This includes confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. The official CVE record and NVD detail page provide critical information for understanding the vulnerability and planning the remediation. Compensating controls for exposed systems, while remediation is scheduled and verified, are essential. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also important. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are key.

Technical summary

The Legora application before version 2026-08-14 contains a cross-site scripting vulnerability. This vulnerability allows attackers to execute arbitrary JavaScript in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive. The front-matter parser invokes eval() before any SVG sanitization occurs, leading to potential JavaScript execution in the user's browser context. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity.

Defensive priority

Medium-priority defensive review recommended due to potential impact on user browser context.

Recommended defensive actions

  • Review and update Legora installations to version 2026-08-14 or later
  • Implement additional input validation and sanitization for Mermaid diagram content
  • Monitor user browser interactions for suspicious activity
  • Consider implementing compensating controls for Word and Outlook add-in surfaces
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The evidence from official CVE and NVD sources confirms a cross-site scripting vulnerability in Legora before 2026-08-14. This vulnerability allows attackers to execute arbitrary JavaScript in a victim's browser through influenced Mermaid diagram content. The CVE record was published on 2026-08-17T20:16:46.813Z and has not been modified since then. The NVD entry is currently Received. Defenders should verify the affected scope, review official advisories, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T20:16:46.813Z and has not been modified since then.