{"id":"CVE-2026-54743","summary":"Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed","details":"Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a sanitizer pass. setupMarkdown configures html as false but registers markdown-it-html5-embed@1.0.0 with useImageSyntax enabled, so an image targeting video media becomes a video element whose fallback incorporates the image alt text through unescaped string replacement. The html setting does not apply to plugin-generated output, allowing crafted alt text to reach the DOM as live HTML in contexts that do not use mdToHtmlNoImages. An approved member or a remote federated instance can store such content, and a viewer who renders it may execute JavaScript in the lemmy-ui origin, exposing the viewer's session and authenticated actions. The advisory notes that Content Security Policy prevents the described exploit in production, but also states that the tested default self-hosted deployment serves no Content-Security-Policy. This issue is fixed in lemmy-ui version 0.19.19-beta.1.","aliases":["GHSA-2g66-9fr3-ppwj"],"modified":"2026-09-11T03:30:15.571954391Z","published":"2026-08-19T20:18:43.124Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54743.json"},"references":[{"type":"WEB","url":"https://github.com/LemmyNet/lemmy/releases/tag/0.19.19-beta.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54743.json"},{"type":"ADVISORY","url":"https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2g66-9fr3-ppwj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54743"},{"type":"FIX","url":"https://github.com/LemmyNet/lemmy-ui/commit/81a3fe07f2a5acc11188320534aa6bf937ebf7ff"},{"type":"FIX","url":"https://github.com/LemmyNet/lemmy-ui/pull/4213"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lemmynet/lemmy","events":[{"introduced":"0"},{"fixed":"50424d6bd059a64fd8d663dd1f5c52619186ba07"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/lemmynet/lemmy-ui","events":[{"introduced":"0"},{"fixed":"81a3fe07f2a5acc11188320534aa6bf937ebf7ff"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.19.19-beta.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.19.19-beta.0","0.19.18","0.19.18-beta.3","0.19.18-beta.1","0.19.18-beta.0","0.19.17","0.19.17-beta.0","0.19.16","0.19.16-beta.1","0.19.16-beta.0","0.19.15","0.19.15-beta.0","0.19.14","0.19.14-beta.2","0.19.14-beta.1","0.19.14-beta.0","0.19.13","0.19.13-beta.1","0.19.12","0.19.12-beta.12","0.19.12-beta.11","0.19.12-beta.10","0.19.12-beta.9","0.19.12-beta.8","0.19.12-beta.7","0.19.12-beta.6","0.19.12-beta.5","0.19.12-beta.4","0.19.12-beta.3","0.19.12-beta.2","0.19.12-beta.1","0.19.12-beta.0","0.19.11","0.19.11-beta.2","0.19.11-beta.1","0.19.11-beta.0","0.19.10","0.19.10-beta.2","0.19.10-beta.1","0.19.10-beta.0","0.19.9","0.19.9-beta.4","0.19.9-beta.3","0.19.9-beta.2","0.19.9-beta.1","0.19.9-beta.0","0.19.8","0.19.8-beta.0","0.19.7","0.19.7-beta.2","0.19.7-beta.1","0.19.6","0.19.6-beta.15","0.19.6-beta.14","0.19.6-beta.9","0.19.6-beta.8","0.19.5","0.19.5-alpha.3","0.19.5-alpha.2","0.19.5-alpha.1","0.19.4","0.19.4-rc.11","0.19.4-rc.10","0.19.4-rc.9","0.19.4-rc.8","0.19.4-rc.7","0.19.4-rc.6","0.19.4-rc.5","0.19.4-rc.4","0.19.4-rc.3","0.19.4-rc.2","0.19.4-rc.1","0.19.4-beta.8","0.19.4-beta.7","0.19.4-beta.6","0.19.4-beta.5","0.19.4-beta.4","0.19.4-beta.3","0.19.4-beta.1","0.19.3","0.19.3-rc.1","0.19.2","0.19.2-rc.5","0.19.2-rc.4","0.19.2-rc.2","0.19.2-rc.1","0.19.1-rc.2","0.19.1-rc.1","0.19.0","0.19.0-rc.16","0.19.0-rc.15","0.19.0-rc.14","0.19.0-rc.13","0.19.0-rc.12","0.19.0-rc.11","0.19.0-rc.10","0.19.0-rc.8","0.19.0-rc.7","0.19.0-rc.6","0.19.0-rc.5","0.19.0-rc.4","0.19.0-rc.3","0.19.0-rc.2","0.19.0-beta.7","0.19.0-rc.1","0.18.4-beta.7","0.18.1","0.18.1-rc.10","0.18.1-rc.9","0.18.1-rc.4","0.18.1-rc.1","0.18.0","0.18.0-rc.8","0.18.0-rc.6","0.18.0-rc.5","0.18.0-rc.4","0.18.0-rc.3","0.18.0-rc.2","0.18.0-rc.1","0.17.1","0.17.0","0.17.0-rc.4","0.17.0-rc.3","0.17.0-rc.1","0.16.5","0.16.3","0.16.3-rc.1","0.16.2","0.16.2-rc.3","0.16.2-rc.2","0.16.2-rc.1","0.16.1","0.16.1-rc.1","0.16.0","0.16.0-rc.4","0.16.0-rc.3","0.16.0-rc.2","0.16.0-rc.1","0.15.1","0.15.0","0.15.0-rc.7","0.14.3","0.14.2","0.14.2-rc.1","0.14.1","0.14.0","0.14.0-rc.2","0.14.0-rc.1","0.13.6-rc.2","0.13.5-rc.7","0.13.0","0.13.0-rc.1","0.12.0","0.12.0-rc.2","0.12.0-rc.1","0.11.4-rc.16","0.11.3-rc.4","0.11.0","0.11.2","0.11.1","0.11.0-rc.1","0.10.2","0.10.1","0.10.0","0.10.0-rc.13","0.10.0-rc.12","0.10.0-rc.7","0.9.9","0.9.8","0.9.7","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.9.0","v0.8.10","v0.8.9","v0.8.8","v0.8.7","v0.8.6","v0.8.5","v0.8.3","v0.8.1","v0.8.0","v0.7.64","v0.7.63","v0.7.62","v0.7.61","v0.7.59","v0.7.57","v0.7.56","v0.7.55","v0.7.54","v0.7.53","v0.7.52","v0.7.50","v0.7.49","v0.7.48","v0.7.43","v0.7.47","v0.7.46","v0.7.44","v0.7.42","v0.7.41","v0.7.40","v0.7.39","v0.7.38","v0.7.37","v0.7.36","v0.7.35","v0.7.34","v0.7.31","v0.7.33","v0.7.32","v0.7.26","v0.7.30","v0.7.29","v0.7.28","v0.7.25","v0.7.24","v0.7.23","v0.7.22","v0.7.21","v0.7.19","v0.7.20","v0.7.18","v0.7.17","v0.7.8","v0.7.7","v0.7.6","v0.7.5","v0.7.4","v0.7.3","v0.5.10","v0.4.0.3","v0.0.8.3","v0.0.8.2","v0.0.8.1","v0.0.7.4","0.19.18-beta.2","0.19.17-beta.1","0.19.14-beta.4","0.19.14-beta.3","0.19.11-beta.3","0.19.8-beta.6","0.19.8-beta.5","0.19.8-beta.4","0.19.8-beta.3","0.19.8-beta.2","0.19.8-beta.1","0.19.6-beta.7","0.19.6-beta.6","0.19.6-beta.5","0.19.6-beta.4","0.19.6-beta.3","0.19.6-beta.2","0.19.4-beta.2","0.19.3-rc.2","0.19.1","0.19.0-rc.9","0.19.0-beta.8","v0.18.2-rc.1","0.18.2-rc.1","0.18.1-rc.11","0.18.1-rc.8","0.18.1-rc.7","0.18.1-rc.5","0.18.1-rc.3","0.18.1-rc.2","0.18.0-rc.7","0.18.0-beta.9","0.17.0-rc.2","0.16.4-rc.10","0.16.3-rc.2","0.15.2","0.15.2-rc.1","0.14.5","0.14.5-rc.2","0.11.4-rc.1","0.11.3-rc.5","0.11.3","0.11.0-rc.3","0.11.0-rc.2","0.10.3","0.10.0-rc.15","0.10.0-rc.14","0.9.8-rc.3","v0.9.7-rc.1","0.9.7-rc.1","0.9.5-rc.1","0.9.0-rc.20","0.9.0-rc.19","0.9.0-rc.18","0.9.0-rc.17","0.9.0-rc.12","0.9.0-rc.7","0.9.0-rc.6","0.9.0-rc.5","v0.9.0-rc.3","0.9.0-rc.4","v0.9.0-rc.2","v0.8.4","v0.8.2","v0.7.60","v0.0.14","v0.0.13","v0.0.12","v0.0.11","v0.0.10","v0.0.9","v0.0.8","v0.0.7","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54743.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}