Description
MarkdownBody, the shared component used to render every Markdown surface in the Paperclip UI (issue documents, issue comments, chat threads, approvals, agent details, export previews, etc.), passes urlTransform={(url) => url} to react-markdown.
Recommendation
Update the @paperclipai/ui package to the latest compatible version. Followings are version details:
- Affected version(s): < 2026.416.0
- Patched version(s): 2026.416.0
References
Could your website be exposed too?
SmartScanner can check your website for Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe - Vulnerability
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML - Vulnerability


