Executive brief
Marko is a programming language used to build web applications. A security flaw in how it handles text inside script and style tags allows attackers to bypass safety filters by using mixed-case letters (like </SCRIPT> instead of </script>). This can lead to cross-site scripting (XSS), allowing an attacker to steal user sessions, take over accounts, or perform unauthorized actions on behalf of users.
Technical details
A cross-site scripting (XSS) vulnerability exists in the Marko runtime due to case-sensitive regular expressions used for escaping. The internal helpers `_escape_script` and `_escape_style` used regex patterns (e.g., `/<\/script/g`) that failed to match mixed-case or uppercase HTML closing tags. Because browsers parse HTML tags case-insensitively, an attacker can provide input containing tags like `</SCRIPT>` to break out of the intended execution context and inject arbitrary JavaScript. This affects any Marko template that interpolates untrusted data directly into script or style blocks. The issue is fixed in Marko version 5.38.36 and @marko/runtime-tags 6.0.164 by implementing case-insensitive matching.
Affected products
- marko-js marko < 5.38.36
- marko-js @marko/runtime-tags < 6.0.164
Timeline
- 2026-04-18: advisory: GitHub Security Advisory published by maintainers
- 2026-05-08: disclosed: CVE published to NVD