HIGH
commenthol
CVE published 2026-06-09
CVE-2026-46492
CVE-2026-46492 is a high-severity cross-site scripting (XSS) vulnerability in md-fileserver's Markdown rendering logic. The vulnerability allows embedded raw HTML, including <script> tags, to be processed and injected into the resulting page without sanitization, enabling arbitrary JavaScript execution. This issue was patched in version 1.10.3. Users of md-fileserver, especially those hosting publicly or [truncated]