Intel

AIKIDO-2026-280543

league/commonmark is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-f8fg-pg57-v4j8 Published Aug 11, 2026

72

High Risk

This Affects:

PHPleague/commonmark
2.7.0 - 2.9.0
Fixed in 2.9.1
Are you affected? Scan for Free

TL;DR

The AttributesExtension filters attribute names such as on* event handlers and unsafe href/src values to stop script injection. Prefixing an attribute name with a form-feed byte lets the name survive trim() and slip past those string comparisons, while browsers still treat the byte as whitespace and parse the name as a genuine attribute. This lets untrusted Markdown inject event handlers or javascript: URIs into rendered HTML, resulting in cross-site scripting even under the recommended hardened configuration. The fix rejects malformed attribute names so form-feed-prefixed names can no longer bypass the filter.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you render untrusted Markdown with the AttributesExtension enabled and its attributes.allow list left at the default empty value.

Background info

league/commonmark is vulnerable to Cross-Site Scripting (XSS) in versions 2.7.0 - 2.9.0.

How to fix this

Upgrade the league/commonmark library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform