Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74234— Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine

CVSS 7.7 · High

Affected Version Matrix 1

VendorProductVersion RangeStatus
LegoraLegora< 2026-08-14affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-74234

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine
Source: CVE Program / CVE List V5
Vulnerability Description
Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive, causing the front-matter parser to invoke eval() before any SVG sanitization occurs. Attackers can exploit this flaw through influenced Mermaid diagram content to execute arbitrary JavaScript in the user's browser context, with elevated impact on Word and Outlook add-in surfaces where bearer session tokens are persisted in localStorage.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
LegoraLegora 0 ~ 2026-08-14 -

II. Public POCs for CVE-2026-74234

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74234

登录查看更多情报信息。

Vendor Advisories for CVE-2026-74234 (1)

Vendor Pages for CVE-2026-74234 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-74234

No comments yet


Leave a comment