216.73.216.226

CVE-2026-46492

· Published 09/06/2026 17:17 · Modified 09/06/2026 20:16

Labels: CVE-2026-46492 2026-06-09CVE-2026-46492CWE-80[email protected]

Essential information

Published
09/06/2026 17:17
Modified
09/06/2026 20:16
Author
Creator
CVSS
7.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CVSS metrics

Description

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary JavaScript execution in the context of the affected domain. This issue has been patched in version 1.10.3.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
md-fileserver / md-fileserver cpe:2.3:a:md-fileserver:md-fileserver:<1.10.3:*:*:*:*:*:*:*

References