{"id":"CVE-2026-5160","aliases":["GHSA-c97m-vxhj-p7j6","GO-2026-5320"],"url":"https://o3.security/vulnerability/CVE-2026-5160","summary":"goldmark vulnerable to Cross-site Scripting (XSS)","details":"Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript&colon;alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.","published":"2026-04-15T05:00:01.655Z","modified":"2026-08-04T18:27:40.182813542Z","cvss":null,"epss":{"score":0.00287,"percentile":0.20845,"asOf":"2026-08-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/yuin/goldmark/renderer/html","fixedVersion":"1.7.17"}],"fix":{"url":"https://github.com/yuin/goldmark/commit/cb46bbc4eca29d55aa9721e04ad207c23ccc44f9","label":"yuin/goldmark@cb46bbc"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMYUINGOLDMARKRENDERERHTML-15838406"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5160.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5160"},{"type":"FIX","url":"https://github.com/yuin/goldmark/commit/cb46bbc4eca29d55aa9721e04ad207c23ccc44f9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-04T18:27:40.182813542Z"}}