CVE-2026-107798: Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter
jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated account that can post messages. They can submit Markdown links containing javascript: URLs or URLs designed to break out of the href attribute.
Are default deployments affected?
Yes. The vulnerable TextStyle rendering filter is described as default-enabled, so deployments using the affected commit range are exposed unless that filter has been disabled or otherwise modified.
What user interaction is required for exploitation?
Other users must interact with a rendered malicious link, such as by clicking it or hovering over it. The resulting JavaScript executes in the affected user's browser.
What can be done if patching is not immediately possible?
Disable the default-enabled TextStyle filter if operationally feasible. Also restrict untrusted users' ability to post messages and remove or sanitize existing messages containing suspicious Markdown link URLs.