Junglewise Threat Intelligence

CVE-2026-47900: Logseq stored XSS in plugin package.json name field

CVE-2026-47900 · Severity: info · CVSS 4.6 · Published 2026-06-09

Technologies: Logseq. Vendors: Logseq.

Executive brief

Logseq, a popular open-source knowledge management and note-taking application, is vulnerable to a security flaw involving its plugin system. A malicious plugin can execute unauthorized code on a user's computer by hiding a script within its configuration file. If a user installs such a plugin, an attacker could potentially gain control over the application and access or modify the user's private notes and data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Logseq due to improper sanitization of plugin metadata. Specifically, the 'name' field within a plugin's 'package.json' file is rendered using the 'innerHTML' property without adequate neutralization. An attacker can craft a malicious plugin containing a JavaScript payload in this field. When the plugin is processed or displayed by the application, the payload executes in the privileged host context. This can be further chained with other reported vulnerabilities in the application's IPC handlers to achieve arbitrary shell command execution or unauthorized filesystem access. As of the advisory date, no patch has been released by the vendor.

Affected products

  • Logseq Logseq All through 0.10.15

Timeline

  • 2026-06-09: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-06-09: advisory: CVE-2026-47900 published

References

Related threats