{"id":"CVE-2019-10905","aliases":["GHSA-62m3-fc7f-jpp8"],"url":"https://o3.security/vulnerability/CVE-2019-10905","summary":"Parsedown Class-Name Injection","details":"Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.","published":"2019-04-06T20:29:00.447Z","modified":"2026-07-08T15:54:28.186383Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01413,"percentile":0.70255,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"erusev/parsedown","fixedVersion":"1.7.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/erusev/parsedown/releases/tag/1.7.2"},{"type":"REPORT","url":"https://github.com/erusev/parsedown/issues/699"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T15:54:28.186383Z"}}