Junglewise Threat Intelligence

CVE-2026-33347: league/commonmark has an embed extension allowed_domains bypass

CVE-2026-33347 · Severity: medium · CVSS 4 · Published 2026-03-19

Technologies: league/commonmark (Packagist). Vendors: Packagist.

Executive brief

league/commonmark has an embed extension allowed_domains bypass

Affected products

  • Packagist league/commonmark

Related threats