CVE-2026-57531 is a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package of Milkdown before 7.21.3. The vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. This vulnerability has a CVSS score of 5.1 and a CVSS severity of MEDIUM. The vulnerability is caused by the p [truncated]
CVE-2026-57530 is a stored cross-site scripting vulnerability in Milkdown, a markdown editor, affecting versions before 7.21.3. The vulnerability exists in the @milkdown/preset-commonmark and @milkdown/components packages, allowing attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The vulnerability aris [truncated]