SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-74234

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Legora versions prior to August 14, 2026, are vulnerable to a cross-site scripting (XSS) flaw that enables attackers to execute arbitrary JavaScript in users' browsers by manipulating Mermaid diagram content. This vulnerability poses a significant risk, particularly for users of Word and Outlook add-ins, as it can lead to unauthorized access to sensitive session tokens stored in localStorage. Organizations utilizing Legora should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-74234
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.