{"id":"CVE-2026-86431","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86431","summary":"league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a…","details":"league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\\x0Conclick=\"alert(1)\"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written verbatim into the output where browsers parse it as a genuine event handler. The same prefix also defeats the allow_unsafe_links check, allowing javascript: URIs through href/src attributes even when allow_unsafe_links is false. Exploitation requires processing untrusted Markdown with the AttributesExtension enabled; the injected script executes when the rendered HTML is viewed. Fixed in 2.9.1.","published":"2026-09-07T13:20:42.460","modified":"2026-09-07T13:20:42.460","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/thephpleague/commonmark/commit/43207253ea5f14867c77c697cd3838c446cadcea","label":"thephpleague/commonmark@4320725"},"references":[{"type":"WEB","url":"https://github.com/thephpleague/commonmark/commit/43207253ea5f14867c77c697cd3838c446cadcea"},{"type":"WEB","url":"https://github.com/thephpleague/commonmark/security/advisories/GHSA-f8fg-pg57-v4j8"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/commonmark-before-2.9.1-xss-via-attributesextension-form-feed-bypass"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T13:20:42.460"}}