{"id":"CVE-2024-36109","summary":"Cross-site Scripting with Markdown rendering in CoCalc","details":"CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `\u003cscript\u003e` tags to be included which execute when published. This issue has been addressed in commit `419862a9c9879c`. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-8w44-hggw-p5rf"],"modified":"2026-08-12T03:51:11.891514212Z","published":"2024-05-28T18:40:55.068Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36109.json","unresolved_ranges":[{"extracted_events":[{"fixed":"419862a9c9879c"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36109.json"},{"type":"ADVISORY","url":"https://github.com/sagemathinc/cocalc/security/advisories/GHSA-8w44-hggw-p5rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36109"},{"type":"FIX","url":"https://github.com/sagemathinc/cocalc/commit/419862a9c9879c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sagemathinc/cocalc","events":[{"introduced":"0"},{"fixed":"419862a9c9879c"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36109.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"}]}