md-editor-v3: XSS via fenced-code language rendering bypass
Published Sep 18, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.33%
Description
md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language value into class and language HTML attributes without escaping or consistently quoting it. Both highlighted and non-highlighted rendering paths reach this return value, while XSSPlugin filters only existing html_block and html_inline tokens before rendering and therefore cannot inspect the renderer-generated HTML. An attacker who can supply Markdown can use crafted fenced-code metadata to execute JavaScript in the application origin when a victim renders it, including as stored cross-site scripting when the host persists the Markdown. This issue is fixed in version 6.5.4
Affected products
-
- Version < 6.5.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Imzbf | MD-Editor-V3 | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
md-editor-v3
npm
Introduced 0 Fixed 6.5.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | md-editor-v3 | 0 | 6.5.4 |
Remediation
No remediation recorded yet.
References (4)
- https://github.com/advisories/GHSA-3rm2-h79c-8qw6 Advisory
- https://github.com/imzbf/md-editor-v3/commit/2c07360420e74087f5bc63032ab155d93e0a0b10 x_refsource_MISC
- https://github.com/imzbf/md-editor-v3/releases/tag/v6.5.4 x_refsource_MISC
- https://github.com/imzbf/md-editor-v3/security/advisories/GHSA-3rm2-h79c-8qw6 exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-3rm2-h79c-8qw6 | Advisory | |
| https://github.com/imzbf/md-editor-v3/commit/2c07360420e74087f5bc63032ab155d93e0a0b10 | x_refsource_MISC | |
| https://github.com/imzbf/md-editor-v3/releases/tag/v6.5.4 | x_refsource_MISC | |
| https://github.com/imzbf/md-editor-v3/security/advisories/GHSA-3rm2-h79c-8qw6 | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.