Medium severity6.1OSV Advisory· Published Dec 30, 2018· Updated Jun 17, 2026
CVE-2018-20583
CVE-2018-20583
Description
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
league/commonmarkPackagist | >= 0.15.6, < 0.18.1 | 0.18.1 |
Affected products
30.1.0, 0.1.1, 0.1.2, …+ 1 more
- (no CPE)range: 0.1.0, 0.1.1, 0.1.2, …
- cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*range: >=0.15.6,<=0.18.0
Patches
Vulnerability mechanics
References
7- github.com/thephpleague/commonmark/issues/337nvdExploitThird Party AdvisoryWEB
- commonmark.thephpleague.com/changelog/nvdRelease NotesThird Party Advisory
- github.com/advisories/GHSA-qx76-c53f-5c7qghsaADVISORY
- github.com/thephpleague/commonmark/releases/tag/0.18.1nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-20583ghsaADVISORY
- commonmark.thephpleague.com/changelogghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/league/commonmark/CVE-2018-20583.yamlghsaWEB
News mentions
0No linked articles in our index yet.