Cross-site scripting in HedgeDoc - #VU127925
Published: April 25, 2026
HedgeDoc
Detailed vulnerability description
The vulnerability allows a remote attacker to trigger browser actions and initiate limited cross-site side effects.
The vulnerability exists due to cross-site scripting in iframe embeddings when rendering embedded webpages. A remote attacker can embed a specially crafted webpage in an iframe to trigger browser actions and initiate limited cross-site side effects.
User interaction is required, and the issue affects instances that allow iframe usage.