{"id":"CVE-2026-22867","summary":"LaSuite Doc affected by Stored XSS via Interlinking Block","details":"LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link. This vulnerability is fixed in 4.4.0.","aliases":["GHSA-4rwv-ghwh-9rv6"],"modified":"2026-08-12T03:51:14.046931127Z","published":"2026-01-15T16:31:34.397Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22867.json"},"references":[{"type":"WEB","url":"https://github.com/suitenumerique/docs/releases/tag/v4.4.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22867.json"},{"type":"ADVISORY","url":"https://github.com/suitenumerique/docs/security/advisories/GHSA-4rwv-ghwh-9rv6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22867"},{"type":"FIX","url":"https://github.com/suitenumerique/docs/commit/e807237dbedbc189230296b81c3aeccc1c04fa77"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/suitenumerique/docs","events":[{"introduced":"b056dbfad418955c4d3688047bbc8983b8b1cd67"},{"fixed":"3d2b0189279f6bc188476e16485cb447fe2a5883"},{"fixed":"e807237dbedbc189230296b81c3aeccc1c04fa77"},{"fixed":"5ec58cef99131f5ecfc3e69031c6a4f4d58b47e6"}],"database_specific":{"extracted_events":[{"introduced":"3.8.0"},{"fixed":"4.3.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:lasuite:docs:*:*:*:*:*:*:*:*"}}],"versions":["v4.3.0-preprod","v4.3.0","v4.2.0-preprod","v4.2.0","v4.1.0-preprod","v4.1.0","v4.0.0-preprod","v4.0.0","v3.10.0-preprod","v3.10.0","v3.9.0-preprod","v3.9.0","v3.8.2-preprod","v3.8.2","v3.8.1-preprod","v3.8.1","v3.8.0-preprod","v3.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22867.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}