Skip to content

CVE-2025-46734 #1713

@justinrclarke

Description

@justinrclarke

league/commonmark contains an XSS vulnerability in the Attributes extension

I just installed the package into a new project and see that it contains a dependency with a registered CVE as of May 15th, 2025.

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions