THREAT OPS › Threat News › [GHSA] GHSA-f8fg-pg57-v4j8 (high) — league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
[GHSA] GHSA-f8fg-pg57-v4j8 (high) — league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
GHSA-f8fg-pg57-v4j8 Severity: high CVE: None
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
### Summary
The `AttributesExtension` documents a security guarantee:
> **Note:** Attributes starting with `on` (e.g. `onclick` or `onerror`) are capable of executing > JavaScript code and are therefore **never allowed by default**. You must e
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- 43207253ea5f14867c77c697cd3838c446cadceasha1
- https://example.com){\x0Chref=url
- https://example.invalid/x.png){\x0Conerror=url
Original source: https://github.com/advisories/GHSA-f8fg-pg57-v4j8