PatchSiren cyber security CVE debrief
CVE-2026-105829 thephpleague CVE debrief
A vulnerability in League CommonMark versions 1.3.0 before 2.10.2 allows for stored cross-site scripting (XSS) via a DisallowedRawHtml bypass. Attackers can exploit this by posting Markdown content that ends raw HTML with a bare disallowed tag name, potentially leading to script execution in viewers' browsers under default GFM settings. This issue affects users who render user-supplied Markdown content, particularly in environments where such content is common. The vulnerability's impact is primarily on the integrity and confidentiality of user data, as it allows for the injection of malicious scripts. To mitigate this, users should update to version 2.10.2 or later of LeagueCommon
- Vendor
- thephpleague
- Product
- commonmark
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and developers using League CommonMark, especially those rendering user-supplied Markdown content, should be aware of this vulnerability and take steps to mitigate it. This includes verifying the version of League CommonMark in use and updating to 2.10.2 or later. Additionally, defenders should review and monitor user-supplied Markdown content for potential XSS exploits and implement additional security measures to detect and prevent XSS attacks.
Why it matters
Defenders should prioritize verifying and updating to version 2.10.2 or later of League CommonMark, especially in environments where user-supplied Markdown content is rendered, to prevent potential stored XSS attacks.
- Potential for stored XSS attacks
- Execution of scripts in viewers' browsers
- Bypass of DisallowedRawHtml extension
- Verification of version updates required
Technical summary
The vulnerability exists in League CommonMark versions 1.3.0 before 2.10.2, allowing attackers to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. This can lead to stored XSS attacks, potentially executing scripts in viewers' browsers under default GFM settings. The technical impact is that an attacker can inject malicious scripts into the rendered Markdown content, affecting the integrity and confidentiality of the content. The vulnerability is primarily related to the handling of raw HTML in Markdown content.
Defensive priority
Defenders should prioritize verifying and updating to version 2.10.2 or later of League CommonMark, especially in environments where user-supplied Markdown content is rendered.
Recommended defensive actions
- Verify and update to version 2.10.2 or later of League CommonMark
- Review and monitor user-supplied Markdown content for potential XSS exploits
- Implement additional security measures to detect and prevent XSS attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, specific details about exploitation or victim impact are not provided. The vulnerability is confirmed to exist in versions 1.3.0 before 2.10.2 of League CommonMark. Defenders should verify the version of League CommonMark in use and update to 2.10.2 or later to mitigate the vulnerability. Evidence of the vulnerability's existence and impact is based on the CVE record and source item descriptions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105829 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105829
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105829 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105829
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105829.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/thephpleague/commonmark/security/advisories/GHSA-97jj-33gv-5xf9
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/league-commonmark-1.3.0-before-2.10.2-stored-xss-via-disallowedrawhtml-bypass
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.