CVE-2026-33347: Thephpleague Commonmark

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

Affected products

  • Thephpleague Commonmark: from 2.3.0, before 2.8.2 (fixed in 2.8.2)

Published 2026-03-24. Last modified 2026-06-17.