Cross-site scripting in Paperclip - #VU141310

 

Cross-site scripting in Paperclip - #VU141310

Published: August 8, 2026


Vulnerability identifier: #VU141310
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser session.

The vulnerability exists due to cross-site scripting in MarkdownBody when rendering markdown links with unsanitized javascript: URLs. A remote user can store a crafted markdown link and trick the victim into clicking it to execute arbitrary script in the victim's browser session.

User interaction is required to click the crafted link, and the issue affects markdown-rendered documents, comments, chat threads, approvals, agent details, export previews, and other markdown surfaces.


Affected software

Paperclip

Remediation

Install security update from vendor's website.

Paperclip - update to 2026.416.0

External References

Related Security Bulletins