PT-2024-26895 · Cocalc · Cocalc

Ishmeals

·

Published

2024-05-28

·

Updated

2024-05-29

·

CVE-2024-36109

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions CoCalc versions prior to the version containing commit 419862a9c9879c
Description The issue concerns the markdown parser in CoCalc, which allows <script> tags to be included and executed when published. There are no known workarounds for this issue.
Recommendations For versions prior to the version containing commit 419862a9c9879c, upgrade to a version that includes the fix.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-36109
GHSA-8W44-HGGW-P5RF

Affected Products

Cocalc