CVE-2026-86431: Thephpleague Commonmark

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written verbatim into the output where browsers parse it as a genuine event handler. The same prefix also defeats the allow_unsafe_links check, allowing javascript: URIs through href/src attributes even when allow_unsafe_links is false. Exploitation requires processing untrusted Markdown with the AttributesExtension enabled; the injected script executes when the rendered HTML is viewed. Fixed in 2.9.1.

Affected products

  • Thephpleague Commonmark: from 2.7.0, before 2.9.1 (fixed in 2.9.1)

Published 2026-09-07. Last modified 2026-10-08.