Cross-site scripting in HedgeDoc - CVE-2021-21259
Published: January 15, 2021 / Updated: April 25, 2026
HedgeDoc
HedgeDoc
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in slide mode when rendering a crafted note. A remote attacker can inject arbitrary JavaScript into a note to execute arbitrary JavaScript in a victim's browser.
Depending on the instance configuration, authentication may not be required to create or edit notes.