SB2021011551 - Cross-site scripting in HedgeDoc
Published: January 15, 2021 Updated: April 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2021-21259)
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in slide mode when rendering a crafted note. A remote attacker can inject arbitrary JavaScript into a note to execute arbitrary JavaScript in a victim's browser.
Depending on the instance configuration, authentication may not be required to create or edit notes.
Remediation
Install update from vendor's website.