CVE-2026-107798mediumCWE-79

CVE-2026-107798: medium-severity vulnerability in banq jivejdon

Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter

Published

10Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.1
exploitation probability
—
observed exploitation
nono source reports it
jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
banq · jivejdon