{"id":"CVE-2020-26298","aliases":["GHSA-q3wr-qw3g-3p4h"],"url":"https://o3.security/vulnerability/CVE-2020-26298","summary":"Injection/XSS in Redcarpet","details":"Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.","published":"2021-01-11T19:15:13.133Z","modified":"2026-07-09T01:30:06.975857Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"redcarpet","fixedVersion":"3.5.1"}],"fix":{"url":"https://github.com/vmg/redcarpet/commit/a699c82292b17c8e6a62e1914d5eccc252272793","label":"vmg/redcarpet@a699c82"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFMYDIONVWATY7EB6EARDVXT47AYCRNM/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNO4ZZUPGAEUXKQL4G2HRIH7CUZKPCT6/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXNNWHHAPREDM3XJDACYRTK7DBMUONBI/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q3wr-qw3g-3p4h"},{"type":"ADVISORY","url":"https://github.com/vmg/redcarpet/blob/master/CHANGELOG.md#version-351-security"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00014.html"},{"type":"ADVISORY","url":"https://rubygems.org/gems/redcarpet"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4831"},{"type":"FIX","url":"https://github.com/vmg/redcarpet/commit/a699c82292b17c8e6a62e1914d5eccc252272793"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:30:06.975857Z"}}