Junglewise Threat Intelligence

CVE-2026-58487: HedgeDoc stored HTML injection via email local-part

CVE-2026-58487 · Severity: info · CVSS 5.1 · Published 2026-07-13

Technologies: HedgeDoc. Vendors: HedgeDoc.

Executive brief

HedgeDoc is an open-source collaborative platform used for creating and sharing markdown notes and presentations. A vulnerability in the account registration process allows an attacker to create an account with a malicious email address that injects unauthorized content into the platform. This could be used to deface shared notes, mislead users with fake information, or embed external content like unauthorized frames into collaborative sessions.

Technical details

HedgeDoc versions prior to 1.11.0 are vulnerable to stored HTML injection due to improper neutralization of the local-part of email addresses during registration. The application accepted RFC 5321 quoted-string local-parts and subsequently reused them as the user's display name without proper escaping. This allowed an authenticated attacker to inject arbitrary HTML markup into publish views, slide views, and the collaborative editor. While a Content Security Policy (CSP) mitigated direct inline JavaScript execution (XSS), attackers could still modify page content and embed cross-origin iframes. The issue is resolved in version 1.11.0 by escaping user-derived display names before rendering.

Affected products

  • HedgeDoc HedgeDoc < 1.11.0

Timeline

  • 2026-06-18: advisory: GitHub Security Advisory published by maintainers
  • 2026-07-13: disclosed: CVE published to NVD

References

Related threats