Unknown · @Diplodoc/Search-Extension · CVE-2026-40201
**Name of the Vulnerable Software and Affected Versions**
@diplodoc/search-extension versions 1.0.0 through 3.0.2
**Description**
Stored Cross-Site Scripting (XSS) occurs via the title in a .md file. Stored XSS is a type of vulnerability where a malicious script is permanently stored on the target server, which then delivers the script to users who visit the affected page.
**Recommendations**
Update to version 3.0.3.