PT-2026-36308 · Unknown · @Diplodoc/Search-Extension

Eyelessg0D

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-40201

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions @diplodoc/search-extension versions 1.0.0 through 3.0.2
Description Stored Cross-Site Scripting (XSS) occurs via the title in a .md file. Stored XSS is a type of vulnerability where a malicious script is permanently stored on the target server, which then delivers the script to users who visit the affected page.
Recommendations Update to version 3.0.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-40201
GHSA-RJMP-RWJ4-MV82

Affected Products

@Diplodoc/Search-Extension