PatchSiren

commenthol CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH commenthol CVE published 2026-06-09

CVE-2026-46492

CVE-2026-46492 is a high-severity cross-site scripting (XSS) vulnerability in md-fileserver's Markdown rendering logic. The vulnerability allows embedded raw HTML, including <script> tags, to be processed and injected into the resulting page without sanitization, enabling arbitrary JavaScript execution. This issue was patched in version 1.10.3. Users of md-fileserver, especially those hosting publicly or [truncated]