Medium severity5.4NVD Advisory· Published May 1, 2026· Updated May 5, 2026
CVE-2026-40201
CVE-2026-40201
Description
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@diplodoc/search-extensionnpm | >= 1.0.0, < 3.0.5 | 3.0.5 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rjmp-rwj4-mv82ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-40201ghsaADVISORY
- github.com/diplodoc-platform/search-extension/pull/41nvdWEB
- github.com/diplodoc-platform/search-extension/releasesnvdWEB
- github.com/diplodoc-platform/search-extension/releases/tag/v3.0.3nvdWEB
- github.com/eyelessgoddd/eyelessgoddd/blob/main/README.mdnvdWEB
News mentions
0No linked articles in our index yet.