CVE-2026-86644 | star7th showdoc up to 3.9.1 API Page Save Endpoint editormd.js cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting.

The identification of this vulnerability is CVE-2026-86644. The attack may be launched remotely. Furthermore, there is an exploit available.

Upgrading the affected component is recommended.

The vendor confirms: “The fix […] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify.”VulDB Recent EntriesRead More