VYPR
High severity8.7OSV Advisory· Published Jan 15, 2026· Updated Jun 17, 2026

CVE-2026-22867

CVE-2026-22867

Description

LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link. This vulnerability is fixed in 4.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Suitenumerique/DocsOSV2 versions
    v3.10.0, v3.10.0-preprod, v3.8.0, …+ 1 more
    • (no CPE)range: v3.10.0, v3.10.0-preprod, v3.8.0, …
    • (no CPE)range: 3.8.0 - 4.3.0
  • cpe:2.3:a:lasuite:docs:*:*:*:*:*:*:*:*
    Range: >=3.8.0,<4.3.0
  • Range: 3.8.0 - 4.3.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.