๐Ÿ” CVE Alert

CVE-2026-86644

LOW 3.5

star7th showdoc API Page Save Endpoint editormd.js cross site scripting

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."

CWE CWE-79 CWE-94
Vendor star7th
Product showdoc
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for star7th showdoc

Be the first to know when new low vulnerabilities affecting star7th showdoc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

star7th / showdoc
3.9.0 3.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/399755 vuldb.com: https://vuldb.com/vuln/399755/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86644 vuldb.com: https://vuldb.com/submit/906282 gist.github.com: https://gist.github.com/saDL0w/36a72a076e9ab24408a3d27582e778b2 github.com: https://github.com/star7th/showdoc/commit/a8ea1520850b4242f395247f72e87e597506cef0 github.com: https://github.com/star7th/showdoc/releases/tag/v3.9.2 github.com: https://github.com/star7th/showdoc/

Credits

๐Ÿ” LIU Tingwei (VulDB User) VulDB CNA Team