CVE-2026-26028 | CryptPad up to 2026.2.0 srcdoc Diffmarked.js sanitizer src cross site scripting
A vulnerability marked as problematic has been reported in CryptPad up to 2026.2.0. Affected is the function sanitizer of the file Diffmarked.js of the component srcdoc Handler. Performing a manipulation of the argument src results in basic cross site scripting.
This vulnerability is known as CVE-2026-26028. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.