Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c97m-vxhj-p7j6 | goldmark vulnerable to Cross-site Scripting (XSS) |
Thu, 23 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:yuin:goldmark:*:*:*:*:*:*:*:* |
Fri, 17 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross-site scripting via URL validation bug in Goldmark HTML renderer | github.com/yuin/goldmark/renderer/html: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yuin
Yuin goldmark |
|
| Vendors & Products |
Yuin
Yuin goldmark |
Wed, 15 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross-site scripting via URL validation bug in Goldmark HTML renderer |
Wed, 15 Apr 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-04-15T18:07:10.025Z
Reserved: 2026-03-30T14:14:48.647Z
Link: CVE-2026-5160
No data.
Status : Analyzed
Published: 2026-04-15T06:16:13.860
Modified: 2026-04-23T17:00:30.137
Link: CVE-2026-5160
OpenCVE Enrichment
Updated: 2026-04-15T14:53:30Z
Github GHSA