PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105829 thephpleague CVE debrief

A vulnerability in League CommonMark versions 1.3.0 before 2.10.2 allows for stored cross-site scripting (XSS) via a DisallowedRawHtml bypass. Attackers can exploit this by posting Markdown content that ends raw HTML with a bare disallowed tag name, potentially leading to script execution in viewers' browsers under default GFM settings. This issue affects users who render user-supplied Markdown content, particularly in environments where such content is common. The vulnerability's impact is primarily on the integrity and confidentiality of user data, as it allows for the injection of malicious scripts. To mitigate this, users should update to version 2.10.2 or later of LeagueCommon

Vendor
thephpleague
Product
commonmark
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders and developers using League CommonMark, especially those rendering user-supplied Markdown content, should be aware of this vulnerability and take steps to mitigate it. This includes verifying the version of League CommonMark in use and updating to 2.10.2 or later. Additionally, defenders should review and monitor user-supplied Markdown content for potential XSS exploits and implement additional security measures to detect and prevent XSS attacks.

Why it matters

Defenders should prioritize verifying and updating to version 2.10.2 or later of League CommonMark, especially in environments where user-supplied Markdown content is rendered, to prevent potential stored XSS attacks.

  • Potential for stored XSS attacks
  • Execution of scripts in viewers' browsers
  • Bypass of DisallowedRawHtml extension
  • Verification of version updates required

Technical summary

The vulnerability exists in League CommonMark versions 1.3.0 before 2.10.2, allowing attackers to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. This can lead to stored XSS attacks, potentially executing scripts in viewers' browsers under default GFM settings. The technical impact is that an attacker can inject malicious scripts into the rendered Markdown content, affecting the integrity and confidentiality of the content. The vulnerability is primarily related to the handling of raw HTML in Markdown content.

Defensive priority

Defenders should prioritize verifying and updating to version 2.10.2 or later of League CommonMark, especially in environments where user-supplied Markdown content is rendered.

Recommended defensive actions

  • Verify and update to version 2.10.2 or later of League CommonMark
  • Review and monitor user-supplied Markdown content for potential XSS exploits
  • Implement additional security measures to detect and prevent XSS attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, specific details about exploitation or victim impact are not provided. The vulnerability is confirmed to exist in versions 1.3.0 before 2.10.2 of League CommonMark. Defenders should verify the version of League CommonMark in use and update to 2.10.2 or later to mitigate the vulnerability. Evidence of the vulnerability's existence and impact is based on the CVE record and source item descriptions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105829 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105829

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105829 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105829

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105829.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/thephpleague/commonmark/security/advisories/GHSA-97jj-33gv-5xf9

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/league-commonmark-1.3.0-before-2.10.2-stored-xss-via-disallowedrawhtml-bypass

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.