VYPR
Medium severity5.4NVD Advisory· Published Oct 8, 2026

CVE-2026-107798

CVE-2026-107798

Description

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Banq/Jivejdonllm-fuzzy
    Range: commit 595d8d22 through commit ee67a65e
  • Range: commit 595d8d22 through commit ee67a65e

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.