{"id":"USN-8194-1","summary":"php-league-commonmark vulnerabilities","details":"It was discovered that league/commonmark did not properly restrict\nunsafe attributes when the Attributes extension was enabled. An attacker\ncould possibly use this issue to cause cross-site scripting by injecting\nmalicious code into rendered HTML. This issue only affected Ubuntu 22.04\nLTS and Ubuntu 24.04 LTS. (CVE-2025-46734)\n\nIt was discovered that league/commonmark did not properly block certain\ndisallowed HTML tags in some cases. An attacker could possibly use this\nissue to cause cross-site scripting by inserting malicious HTML that\nbypassed filtering. (CVE-2026-30838)\n\nIt was discovered that league/commonmark did not properly enforce domain\nallowlist checks in the Embed extension. An attacker could possibly use\nthis issue to bypass domain restrictions and cause untrusted content to\nbe treated as allowed. This issue only affected Ubuntu 24.04 LTS.\n(CVE-2026-33347)","modified":"2026-04-24T10:25:40.206469Z","published":"2026-04-21T17:25:51Z","upstream":["CVE-2025-46734","CVE-2026-30838","CVE-2026-33347","UBUNTU-CVE-2025-46734","UBUNTU-CVE-2026-30838","UBUNTU-CVE-2026-33347"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8194-1"}],"affected":[{"package":{"name":"php-league-commonmark","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/php-league-commonmark@1.3.1-1ubuntu2+esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1-1ubuntu2+esm1"}]}],"versions":["1.1.2-1","1.2.0-1","1.3.0-1","1.3.1-1","1.3.1-1ubuntu2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.3.1-1ubuntu2+esm1","binary_name":"php-league-commonmark"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8194-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:20.04:LTS"}}},{"package":{"name":"php-league-commonmark","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/php-league-commonmark@1.6.7-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.7-1ubuntu0.1~esm1"}]}],"versions":["1.5.7-2build1","1.6.6-1build1","1.6.7-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.6.7-1ubuntu0.1~esm1","binary_name":"php-league-commonmark"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8194-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:22.04:LTS"}}},{"package":{"name":"php-league-commonmark","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/php-league-commonmark@2.4.2-2ubuntu0.1~esm1?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.2-2ubuntu0.1~esm1"}]}],"versions":["2.3.9-1","2.4.1-1","2.4.2-1","2.4.2-2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"2.4.2-2ubuntu0.1~esm1","binary_name":"php-league-commonmark"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8194-1.json","cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:24.04:LTS"}}}],"schema_version":"1.7.5"}