VYPR
High severity8.3NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026

CVE-2020-27176

CVE-2020-27176

Description

Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Marktext/Marktext2 versions
    cpe:2.3:a:marktext:marktext:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:marktext:marktext:*:*:*:*:*:*:*:*range: <=0.16.2
    • (no CPE)range: <=0.16.2
  • Mark Text/Mark Textdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.