Junglewise Threat Intelligence

CVE-2025-46734: league/commonmark XSS in Attributes extension

CVE-2025-46734 · Severity: medium · CVSS 6.4 · Published 2025-05-05

Technologies: league/commonmark (Packagist), The PHP League CommonMark. Vendors: Packagist, The PHP League.

Executive brief

The league/commonmark library, a popular tool for converting Markdown text into HTML, contains a vulnerability in its Attributes extension. This flaw allows attackers to bypass security settings and inject malicious JavaScript into web pages. If exploited, this could lead to unauthorized actions being performed in a user's browser, potentially compromising user data or session security.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x). While the library offers 'strip' and 'allow_unsafe_links' configurations to mitigate XSS, the Attributes extension allows users to inject arbitrary HTML attributes using curly brace syntax (e.g., {onerror=...}). An attacker can use this to bypass filters and execute JavaScript on page load. The vulnerability is addressed in version 2.7.0 by blocking 'on*' attributes by default, introducing an attribute allowlist, and ensuring manually added links respect existing safety configurations.

Affected products

  • league commonmark >= 1.5.0, < 2.7.0

Timeline

  • 2025-05-05: disclosed
  • 2025-05-05: advisory
  • 2025-05-05: patched: Fixed in version 2.7.0

References

Related threats