{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105829", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-05T21:59:09.591Z", "datePublished": "2026-10-08T14:10:30.523Z", "dateUpdated": "2026-10-08T15:22:12.780Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T15:22:12.780Z" }, "datePublic": "2026-09-21T00:00:00.000Z", "title": "League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass", "descriptions": [ { "lang": "en", "value": "League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone