CVE-2026-86644: Cross Site Scripting in star7th showdoc
A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."
AI Analysis
Technical Summary
CVE-2026-86644 is a cross-site scripting vulnerability affecting star7th showdoc up to version 3.9.1. The vulnerability is located in the file web_src/public/editor.md/editormd.js within the API Page Save Endpoint component. Remote attackers can exploit this flaw by manipulating input to execute arbitrary scripts. The vendor fixed the issue in version 3.9.2 by setting Mermaid's securityLevel to strict, disabling htmlLabels, and sanitizing rendered SVG content using DOMPurify. The vulnerability has a CVSS 4.0 base score of 5.1 (medium severity).
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of the affected application, potentially leading to session hijacking or other client-side impacts. The vulnerability requires low attack complexity and no privileges but does require user interaction. There is no indication of elevated privileges or system-level compromise.
Mitigation Recommendations
Upgrade star7th showdoc to version 3.9.2 or later, which includes the official fix. The vendor's patch enforces stricter security settings and sanitizes SVG content to prevent XSS. No additional mitigations are indicated by the vendor.
CVE-2026-86644: Cross Site Scripting in star7th showdoc
Description
A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."
CVSS v4.0
Score 5.1medium
Affected software
pkg:github/star7th/showdoccpe:2.3:a:showdoc:showdoc:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86644 is a cross-site scripting vulnerability affecting star7th showdoc up to version 3.9.1. The vulnerability is located in the file web_src/public/editor.md/editormd.js within the API Page Save Endpoint component. Remote attackers can exploit this flaw by manipulating input to execute arbitrary scripts. The vendor fixed the issue in version 3.9.2 by setting Mermaid's securityLevel to strict, disabling htmlLabels, and sanitizing rendered SVG content using DOMPurify. The vulnerability has a CVSS 4.0 base score of 5.1 (medium severity).
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of the affected application, potentially leading to session hijacking or other client-side impacts. The vulnerability requires low attack complexity and no privileges but does require user interaction. There is no indication of elevated privileges or system-level compromise.
Mitigation Recommendations
Upgrade star7th showdoc to version 3.9.2 or later, which includes the official fix. The vendor's patch enforces stricter security settings and sanitizes SVG content to prevent XSS. No additional mitigations are indicated by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-08T09:15:24.988Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa00fe7acd9273b49b87b8e
Added to database: 09/08/2026, 13:38:47 UTC
Last enriched: 09/08/2026, 13:52:53 UTC
Last updated: 09/09/2026, 02:30:21 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.