MEDIUM 4.3
GHSA-5cmv-3rc4-7279
Weblate vulnerable to XSS via crafted Markdown
상세
### Impact The Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes.
### Patches * https://github.com/WeblateOrg/weblate/pull/19259
### Workarounds Even though the attacker might be able to inject code into the HTML, the Weblate's strict CSP should mitigate the risks.
### Acknowlegement Michal Čihař has identified and fixed this vulnerability.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-5cmv-3rc4-7279 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44264 [ADVISORY]
- https://github.com/WeblateOrg/weblate/pull/19259 [WEB]
- https://github.com/WeblateOrg/weblate/commit/85abc9df88b7464f4c0e794aef752e45f4230f75 [WEB]
- https://github.com/WeblateOrg/weblate [PACKAGE]
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.17.1 [WEB]