MEDIUM
Legora
CVE published 2026-08-17
CVE-2026-74234
The Legora application before version 2026-08-14 contains a cross-site scripting vulnerability, allowing attackers to execute arbitrary JavaScript in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. Users of Legora before version 2026-08-14, administrators of syste [truncated]