MEDIUM
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file
Published May 1, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.30%
Description
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<3.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Diplodoc-Platform | n/a | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
@diplodoc/search-extension
npm
Introduced 1.0.0 Fixed 3.0.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @diplodoc/search-extension | 1.0.0 | 3.0.5 |
Remediation
Vendor solution
Use the function escapeHtml within highlighte.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-rjmp-rwj4-mv82 Advisory
- https://github.com/diplodoc-platform/search-extension/pull/41
- https://github.com/diplodoc-platform/search-extension/releases
- https://github.com/diplodoc-platform/search-extension/releases/tag/v3.0.3
- https://github.com/eyelessgoddd/eyelessgoddd/blob/main/README.md
- https://nvd.nist.gov/vuln/detail/CVE-2026-40201
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 1, 2026
Updated May 5, 2026
Reserved Apr 10, 2026
Link CVE-2026-40201
CISA Vulnrichment
GHSA-RJMP-RWJ4-MV82 Updated May 1, 2026