CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-57531

MEDIUM
5.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-24
Last Modified2026-07-25
Data SourcesNVD

Vulnerability Description

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs handler stores raw innerHTML of pasted span elements with data-type="emoji" without sanitization, and the toMarkdown runner subsequently assigns this unsanitized value directly to a live DOM element's innerHTML, bypassing the DOMPurify sanitization used in the toDOM path, causing payload execution on every markdown serialization cycle.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁