Executive brief
Typemill is a flat-file, Markdown-based content management system used for building documentation websites. A vulnerability in versions before 2.23.0 allows authenticated users with metadata editing permissions to inject malicious HTML into Open Graph meta tags (used for social media previews and search engines). This could lead to stored cross-site scripting attacks that execute in visitors' browsers, potentially compromising session cookies or sensitive information.
Technical details
The vulnerability is a stored HTML attribute injection (CWE-79) in the renderMeta() function within system/typemill/Assets.php. User-supplied metadata values for og:title and og:description are inserted into meta tag attributes without HTML entity encoding, allowing an authenticated attacker to break out of the content attribute via a double-quote character and inject arbitrary HTML attributes. The attack vector requires network access, valid credentials (privilege level: low), and user interaction in the browser. An attacker can inject payloads like XSS" onmouseover="alert(1)" x=" to execute JavaScript. The backend API endpoint /api/v1/meta did not sufficiently validate or encode special characters before rendering. Version 2.23.0 fixes the issue by applying htmlspecialchars() with ENT_QUOTES encoding to all metadata values.
Affected products
- Typemill Typemill prior to 2.23.0
Timeline
- 2026-05-30: disclosed
- 2026-05-17: patched: Version 2.23.0 released