๐Ÿ” CVE Alert

CVE-2026-74234

HIGH 7.7

Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive, causing the front-matter parser to invoke eval() before any SVG sanitization occurs. Attackers can exploit this flaw through influenced Mermaid diagram content to execute arbitrary JavaScript in the user's browser context, with elevated impact on Word and Outlook add-in surfaces where bearer session tokens are persisted in localStorage.

CWE CWE-95
Vendor legora
Product legora
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for legora legora

Be the first to know when new high vulnerabilities affecting legora legora are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Legora / Legora
0 < 2026-08-14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
legora.com: https://legora.com/ vulncheck.com: https://www.vulncheck.com/advisories/legora-2026-08-14-xss-via-mermaid-gray-matter-javascript-engine

Credits

Mobasi Security Team