CVE-2026-107798: Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter

Published Oct 8, 2026
·
Updated

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

Affected Software

1 affected component
jivejdon

Event History

Oct 8, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an authenticated account that can post messages. They can submit Markdown links containing javascript: URLs or URLs designed to break out of the href attribute.

2

Are default deployments affected?

Yes. The vulnerable TextStyle rendering filter is described as default-enabled, so deployments using the affected commit range are exposed unless that filter has been disabled or otherwise modified.

3

What user interaction is required for exploitation?

Other users must interact with a rendered malicious link, such as by clicking it or hovering over it. The resulting JavaScript executes in the affected user's browser.

4

What can be done if patching is not immediately possible?

Disable the default-enabled TextStyle filter if operationally feasible. Also restrict untrusted users' ability to post messages and remove or sanitize existing messages containing suspicious Markdown link URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203