Description
A cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including
Recommendation
Update the md-fileserver package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.10.3
- Patched version(s): 1.10.3
References
Could your website be exposed too?
SmartScanner can check your website for md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @diplodoc/search-extension allows stored XSS via Markdown file title - CVE-2026-40201
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
- Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` - CVE-2026-44990
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721


