CVE-2026-86644 Details
Description
A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."
A stored cross-site scripting vulnerability has been identified in Star7th ShowDoc versions through 3.9.1. The issue resides in the API page save endpoint, specifically within the 'web_src/public/editor.md/editormd.js' file. The vulnerability allows for the injection of malicious scripts that are executed when the affected content is viewed. This issue has been publicly disclosed and can be exploited remotely.
Users are advised to upgrade to Star7th ShowDoc version 3.9.2, which addresses the vulnerability by sanitizing rendered SVG with DOMPurify and adjusting the Mermaid security settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/saDL0w/36a72a076e9ab24408a3d27582e778b2 | [email protected] | ExploitTechnical Description |
| https://github.com/star7th/showdoc/ | [email protected] | ProductVendor |
| https://github.com/star7th/showdoc/commit/a8ea1520850b4242f395247f72e87e597506cef0 | [email protected] | Source CodeVendor |
| https://github.com/star7th/showdoc/releases/tag/v3.9.2 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-86644 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/906282 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399755 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/399755/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| star7th ShowDoc | >= 3.7.1, <= 3.9.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion