{"id":"CVE-2021-43827","details":"discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in `\u003ca\u003e` tags (e.g. `\u003ca\u003e^[footnote]\u003c/a\u003e`, the resulting rendered HTML would include a nested `\u003ca\u003e`, which is stripped by Nokogiri because it is not valid. This then caused a javascript error on topic pages because we were looking for an `\u003ca\u003e` element inside the footnote reference span and getting its ID, and because it did not exist we got a null reference error in javascript. Users are advised to update to version 0.2. As a workaround editing offending posts from the rails console or the database console for self-hosters, or disabling the plugin in the admin panel can mitigate this issue.","aliases":["GHSA-58vr-c56v-qr57"],"modified":"2026-07-08T06:29:52.990097957Z","published":"2021-12-14T23:15:08.020Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"discourse:discourse_footnote","cpes":["cpe:2.3:a:discourse:discourse_footnote:*:*:*:*:*:discourse:*:*"],"extracted_events":[{"fixed":"0.2"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/discourse/discourse-footnote/security/advisories/GHSA-58vr-c56v-qr57"},{"type":"FIX","url":"https://github.com/discourse/discourse-footnote/commit/796617e0131277011207541313522cd1946661ab"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/discourse/discourse-footnote","events":[{"introduced":"0"},{"fixed":"796617e0131277011207541313522cd1946661ab"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43827.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}