Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
A flaw in league/commonmark (the popular PHP Markdown library) lets planted text run scripts in your users' browsers.
It slips past allow_unsafe_links=false, the 'safe mode' for untrusted Markdown.
Affects 1.5.0-2.8.3 with the Attributes extension. Fix: 2.9.0. CVE-2026-71478
https://suriq.io/blog/commonmark-attributes-xss-cve-2026-71478
2026-08-07T08:30:28.574Z