Junglewise Threat Intelligence

CVE-2026-48788: Remark42 Cross-Site Scripting via image proxy content-type spoofing

CVE-2026-48788 · Severity: high · CVSS 8.2 · Published 2026-06-17

Vendors: Go.

Executive brief

Remark42, a popular self-hosted commenting system, contains a vulnerability in its image proxy service. An attacker can trick the system into serving malicious scripts disguised as images. If a user (especially an administrator) clicks a specially crafted link, the attacker can execute commands in their browser, potentially allowing them to delete comments, change settings, or take over the account.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Remark42's image proxy (/api/v1/img) due to an interpretation conflict between the downloader and the server. The downloader validates the 'Content-Type' header from a remote source without inspecting the actual payload bytes. When serving the cached content, the application uses 'http.DetectContentType' to sniff the body, which may identify malicious HTML/JavaScript as 'text/html'. An attacker can host a malicious file that claims to be an image but contains a script. When a victim visits a crafted proxy URL, the script executes in the context of the Remark42 origin, allowing the attacker to bypass CSRF protections and access authenticated API endpoints using the victim's session. This is fixed in version 1.16.0 by implementing strict content-type allowlisting and defensive security headers.

Affected products

  • umputun remark42 >= 1.6.0, < 1.16.0

Timeline

  • 2026-05-22: disclosed
  • 2026-06-17: advisory: NVD publication
  • 2026-06-26: patched: GitHub Advisory published/reviewed

References