CVE-2024-56082

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.

Published 2024-12-15. Last modified 2026-06-17.