
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30838 is a Cross-Site Scripting (XSS) vulnerability in the league/commonmark PHP library's DisallowedRawHtml extension that allows attackers to bypass HTML tag filtering by inserting ASCII whitespace characters (newline, tab, etc.) between a disallowed tag name and its closing >. It affects versions 2.0.0 through 2.8.0 of the league/commonmark Composer package. The vulnerability was published by maintainer colinodell on March 5, 2026, and added to the GitHub Advisory Database on March 6, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Vendor Advisory).
The root cause is improper input neutralization (CWE-79, CWE-80) in the regex used by the DisallowedRawHtml extension to detect and block disallowed HTML tags. The original regex character class [ \/>]only matched a space, forward slash, or>as valid tag name terminators, failing to account for other ASCII whitespace characters (e.g.,\n, \t) that browsers also accept as valid terminators. An attacker can craft a markdown payload such as <script\n>— where a newline separates the tag name from>— which passes through the filter undetected and is rendered as a functional<script>tag by browsers. The fix in version 2.8.1 changes the character class to[\s/>] to match all whitespace characters (GitHub Advisory, Vendor Advisory).
Successful exploitation enables stored or reflected XSS attacks against users of any application that relies solely on the DisallowedRawHtml extension to sanitize untrusted markdown input. An attacker can inject and execute arbitrary JavaScript in victims' browsers, potentially leading to session hijacking, credential theft, unauthorized actions on behalf of the victim, or further client-side attacks. Applications that additionally pass rendered HTML through a dedicated sanitizer such as HTML Purifier are not affected. Availability is not impacted by this vulnerability (GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-30838 as of the available data. The EPSS score is approximately 0.047% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to submit crafted markdown content to an application that renders it for other users, and a victim must view the rendered output — making it a low-complexity but user-interaction-dependent attack (GitHub Advisory).
league/commonmark versions 2.0.0–2.8.0 with the DisallowedRawHtml extension enabled to process untrusted user-supplied markdown (e.g., comment fields, wiki pages, issue trackers).<script>) with an ASCII whitespace character inserted between the tag name and the closing >, such as:<script
>alert(document.cookie)</script
><script\n>, <iframe\t>) in markdown input fields.\n), tab (\t), or other whitespace before the closing > (e.g., <script\n>, <object\r>).The vulnerability is fixed in league/commonmark version 2.8.1; operators should upgrade immediately via Composer (composer update league/commonmark). As a workaround, set the html_input configuration option to 'escape' or 'strip' to disable all raw HTML processing, though this is broader than the DisallowedRawHtml extension's intended scope. Additionally, passing all rendered HTML output through a dedicated HTML sanitizer such as HTML Purifier before serving it to users is strongly recommended as a defense-in-depth measure regardless of the patch status (GitHub Advisory, Vendor Advisory).
Red Hat acknowledged the vulnerability and published a CVE entry on March 9, 2026 (Red Hat CVE). Tenable released Nessus detection plugins (IDs 301662 and 309186) for the vulnerability. Ubuntu issued a security advisory (USN-8194-1) covering league/commonmark, and downstream projects such as Snipe-IT released updated versions (v8.4.1) incorporating the fix. Community coverage was noted on security aggregators and social platforms shortly after disclosure.
Fix availability across major Linux distributions and their releases.
bookworm
php-league-commonmark: 2.3.9-1+deb12u1
sid
php-league-commonmark: 2.8.1-1
trixie
php-league-commonmark: 2.7.0-1+deb13u1
devel
php-league-commonmark
focal (esm-apps)
php-league-commonmark: 1.3.1-1ubuntu2+esm1
jammy
php-league-commonmark
jammy (esm-apps)
php-league-commonmark: 1.6.7-1ubuntu0.1~esm1
noble
php-league-commonmark
noble (esm-apps)
php-league-commonmark: 2.4.2-2ubuntu0.1~esm1
resolute
php-league-commonmark
resolute (esm-apps)
php-league-commonmark
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."