Cross-site scripting in Paperclip - #VU141310
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser session.
The vulnerability exists due to cross-site scripting in MarkdownBody when rendering markdown links with unsanitized javascript: URLs. A remote user can store a crafted markdown link and trick the victim into clicking it to execute arbitrary script in the victim's browser session.
User interaction is required to click the crafted link, and the issue affects markdown-rendered documents, comments, chat threads, approvals, agent details, export previews, and other markdown surfaces.