What is CVE-2026-74234?
CVE-2026-74234 is an XSS vulnerability in Legora versions prior to 2026-08-14, triggered by a crafted Mermaid block with a JavaScript front-matter directive that causes the parser to invoke eval(), allowing arbitrary code execution in the victim's browser. Immediately apply the security update to mitigate this risk.
Azərbaycanca: CVE-2026-74234: Legora proqramının 2026-08-14 tarixindən əvvəlki versiyalarında aşkar edilmiş cross-site scripting (XSS) boşluğudur. Təcavüzkar, xüsusi hazırlanmış Mermaid bloku və JavaScript front-matter direktivindən istifadə edərək istifadəçinin brauzerində eval() funksiyasını işə salıb, ixtiyari kod icra edə bilər. Dərhal təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can an attacker achieve arbitrary code execution using CVE-2026-74234?
The attacker uses a crafted Mermaid block with a JavaScript front-matter directive to cause the parser to invoke eval(), enabling arbitrary code execution in the victim's browser.
What should be done to mitigate the risk of CVE-2026-74234?
Versions of Legora prior to 2026-08-14 are affected, so it is recommended to immediately apply the security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.