CVE-2026-84992: md-editor-v3: XSS via fenced-code language rendering bypass
MdPreview interpolates a fenced-code language into HTML attributes without escaping it. A crafted info string therefore executes JavaScript even when the shipped XSSPlugin is enabled.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-84992 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →