THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f8fg-pg57-v4j8 (high) — league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

[GHSA] GHSA-f8fg-pg57-v4j8 (high) — league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

highgithub_advisoriesPublished 2026-09-01

GHSA-f8fg-pg57-v4j8 Severity: high CVE: None

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

### Summary

The `AttributesExtension` documents a security guarantee:

> **Note:** Attributes starting with `on` (e.g. `onclick` or `onerror`) are capable of executing > JavaScript code and are therefore **never allowed by default**. You must e

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f8fg-pg57-v4j8