What is CVE-2026-57530?
CVE-2026-57530 is a stored cross-site scripting (XSS) vulnerability in Milkdown before version 7.21.3, affecting the @milkdown/preset-commonmark and @milkdown/components packages. It allows attackers with document write access to execute arbitrary JavaScript in the browser of users who open the document or view the rendered content. Updating to Milkdown 7.21.3 or later is strongly recommended.
Azərbaycanca: CVE-2026-57530, Milkdown markdown redaktorunun 7.21.3 versiyasından əvvəlki versiyalarında @milkdown/preset-commonmark və @milkdown/components paketlərində aşkarlanan saxlanılmış cross-site scripting (stored XSS) zəifliyidir. Bu zəiflik, sənəd yazma icazəsi olan hücumçulara sənədi açan və ya emal edilən kontenti görüntüləyən istənilən istifadəçinin brauzerində icazəsiz JavaScript kodunu icra etməyə imkan verir. Ən qısa zamanda Milkdown 7.21.3 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which Milkdown components are affected by CVE-2026-57530?
This stored XSS vulnerability affects the @milkdown/preset-commonmark and @milkdown/components packages.
What action should be taken to protect against CVE-2026-57530?
Updating to Milkdown 7.21.3 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.