CVE-2026-86431 | thephpleague commonmark up to 2.9.0 AttributesExtension filterAttributes cross site scripting

SecurityVulns

A vulnerability categorized as problematic has been discovered in thephpleague commonmark up to 2.9.0. The impacted element is the function AttributesHelper::filterAttributes of the component AttributesExtension. The manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-86431. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More