SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-54743

MEDIUM · CVSS 6.4 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Lemmy platform, specifically its handling of Markdown rendering in the lemmy-ui component, which can lead to the injection of unescaped HTML through crafted alt text in images. This flaw allows approved members or remote federated instances to execute JavaScript in the context of the viewer's session, potentially compromising user authentication and actions. Organizations using Lemmy, especially those self-hosting without a Content Security Policy, should prioritize upgrading to version 0.19.19-beta.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54743
Severity
MEDIUM
CVSS
6.4
EPSS
0.51%
Java

Original NVD Description

Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a sanitizer pass. setupMarkdown configures html as false but registers markdown-it-html5-embed@1.0.0 with useImageSyntax enabled, so an image targeting video media becomes a video element whose fallback incorporates the image alt text through unescaped string replacement. The html setting does not apply to plugin-generated output, allowing crafted alt text to reach the DOM as live HTML in contexts that do not use mdToHtmlNoImages. An approved member or a remote federated instance can store such content, and a viewer who renders it may execute JavaScript in the lemmy-ui origin, exposing the viewer's session and authenticated actions. The advisory notes that Content Security Policy prevents the described exploit in production, but also states that the tested default self-hosted deployment serves no Content-Security-Policy. This issue is fixed in lemmy-ui version 0.19.19-beta.1.