Vulnerabilities/

CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS

Severity:
Medium

Description

CryptPad’s HTML sanitizer in Diffmarked.js can be bypassed due to incomplete filtering of restricted tags. Because the sanitizer only validates the src attribute of <iframe> <video>, and <audio> elements, and does not restrict other attributes, an attacker can inject arbitrary HTML through srcdoc.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
cryptpad
Anything's wrong? Let us know Last updated on May 26, 2026