VYPR

Milkdown

by Milkdown

CVEs (2)

  • CVE-2026-57531Jul 24, 2026
    risk 0.00cvss epss 0.00

    Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The…

  • CVE-2026-57530Jul 24, 2026
    risk 0.00cvss epss 0.00

    Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the…