High severity8.7OSV Advisory· Published Jan 15, 2026· Updated Jun 17, 2026
CVE-2026-22867
CVE-2026-22867
Description
LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link. This vulnerability is fixed in 4.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4v3.10.0, v3.10.0-preprod, v3.8.0, …+ 1 more
- (no CPE)range: v3.10.0, v3.10.0-preprod, v3.8.0, …
- (no CPE)range: 3.8.0 - 4.3.0
- Range: 3.8.0 - 4.3.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.