VYPR

Logseq

by Logseq

Source repositories

CVEs (5)

  • CVE-2026-9279HigJun 9, 2026
    risk 0.57cvss epss 0.00

    Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, `grep`), the argument string is concatenated with the command and passed to `child_process.spawn` with the `shell: true`…

  • CVE-2026-47899HigJun 9, 2026
    risk 0.57cvss epss 0.00

    The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript execution in the renderer (e.g. via XSS or a malicious plugin), can read, write, or delete arbitrary…

  • CVE-2025-56683CriOct 9, 2025
    risk 0.55cvss 9.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted README.md file.

  • CVE-2026-47901MedJun 9, 2026
    risk 0.30cvss epss 0.00

    Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to…

  • CVE-2026-47900MedJun 9, 2026
    risk 0.30cvss epss 0.00

    Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" without proper sanitization, allowing the execution of arbitrary code in the…