CVE-2026-105829 | PHP League CommonMark up to 1.2.x/2.10.1 DisallowedRawHtml Extension HTML injection

SecurityVulns

A vulnerability was found in PHP League CommonMark up to 1.2.x/2.10.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the component DisallowedRawHtml Extension. The manipulation leads to HTML injection.

This vulnerability is uniquely identified as CVE-2026-105829. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More