@diplodoc/search-extension allows stored XSS via Markdown file title
- Severity:
- Medium
Description
@diplodoc/search-extension 1.0.0 through 3.0.2 allows stored XSS via .md file title.
Recommendation
Update the @diplodoc/search-extension package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.0.0, < 3.0.5
- Patched version(s): 3.0.5
References
Related Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - CVE-2026-46396
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player - CVE-2026-46396
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
You might also like:
- Tags:
- npm
- @diplodoc/search-extension
Anything's wrong? Let us know Last updated on May 07, 2026


