CVE-2026-86644 | star7th showdoc up to 3.9.1 API Page Save Endpoint editormd.js cross site scripting
A vulnerability described as problematic has been identified in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-86644. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
The vendor confirms: “The fix […] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify.”VulDB Recent EntriesRead More